Malicious PDF — malware analysis report

Static analysis result for SHA-256 548cc585f1380b12…

MALICIOUS

PDF

72.9 KB Created: 2021-01-19 17:55:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a5973d00c1b6fb7af8c2326ebead9455 SHA-1: dea1938a31ab9a2fd1265fe6a8309c95d26985ce SHA-256: 548cc585f1380b120b1ada132d928c3e6a93037d77bf30a0322622d1dab6b16e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, indicating a link farm designed to drive traffic to various websites. The primary URL, https://maypoin.ru/aws?utm_term=hometown+glory+sheet+music+free+pdf, suggests a lure related to free sheet music. While no scripts were directly extracted, the PDF structure and numerous embedded URLs strongly suggest malicious intent, likely for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/aws?utm_term=hometown+glory+sheet+music+free+pdf
    • https://static.s123-cdn-static.com/uploads/4370746/normal_5fcf0448cb87a.pdf
    • https://static.s123-cdn-static.com/uploads/4417669/normal_5fc7f10a9ab1f.pdf
    • https://cdn.sqhk.co/xarozowuzosa/bX0kgdD/dragon_ball_z_dokkan_battle_apk_mod_jp.pdf
    • https://cdn-cms.f-static.net/uploads/4495997/normal_5fb262d95604e.pdf
    • https://static.s123-cdn-static.com/uploads/4475571/normal_60006eb2bb808.pdf
    • https://cdn-cms.f-static.net/uploads/4449605/normal_5fbe52e3bbd7b.pdf
    • https://cdn-cms.f-static.net/uploads/4391642/normal_5fb4f2e239460.pdf
    • https://cdn-cms.f-static.net/uploads/4369648/normal_5fc26116a7cf2.pdf
    • https://static.s123-cdn-static.com/uploads/4452152/normal_5ffa232ecbfb6.pdf
    • https://cdn-cms.f-static.net/uploads/4450345/normal_5fb9a22bd8e96.pdf
    • https://popilezofale.weebly.com/uploads/1/3/1/1/131164236/fitok-xovozujaled-texel-jolekokovudamo.pdf
    • https://static.s123-cdn-static.com/uploads/4408989/normal_600520e77cbdc.pdf
    • https://static.s123-cdn-static.com/uploads/4379477/normal_5fdd8965d15c1.pdf
    • https://cdn-cms.f-static.net/uploads/4478438/normal_5fd7c0cccbb74.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/xezonijida/rusulo.pdf
    • https://s3.amazonaws.com/kijelopazekune/6697013765.pdf
    • https://s3.amazonaws.com/rupatojuko/povemerivuxi.pdf
    • https://s3.amazonaws.com/padosumifubobo/37974193890.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cf67.bin
781cb69320852a5aa6b5dd0b1dbac99ed7fc4ed9e3b3fb5c7a6d56b183d0a7f7
pdf-font-stream PDF embedded font (sfnt) at offset 0xCF67 5516 bytes
font_01_sfnt_off0000e220.bin
0ebafb7cdd5a56a5a39664fbc3d8ad715f12b05a00ca1b814091622026fc14e6
pdf-font-stream PDF embedded font (sfnt) at offset 0xE220 15996 bytes