Malicious PDF — malware analysis report

Static analysis result for SHA-256 58576bcaca51afb4…

MALICIOUS

PDF

80.8 KB Created: 2021-04-06 05:47:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5826fa173687602a2daabe995def9a7a SHA-1: 9a9045803591683eccaac15ae79ddbbbdd106dfb SHA-256: 58576bcaca51afb43ae9992cae9770a1a790621896e8f665d897f723f2c75f3f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a malicious intent to direct users to potentially harmful websites. The ClamAV detection and ML classifier further support its malicious nature. While no scripts were directly extracted, the presence of numerous external URIs indicates a phishing or SEO manipulation attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=why+us+has+bases+in+germany
    • http://pozufopajosel.mypressonline.com/estado_civil_definicion.pdf
    • http://tapopapebesawu.getenjoyment.net/que_es_el_diagnostico_situacional_en_enfermeria.pdf
    • http://fesurowejo.mywebcommunity.org/ways_to_prevent_climate_change_at_school.pdf
    • http://tokiridevifo.medianewsonline.com/blood_cancer_positive_report.pdf
    • https://cdn-cms.f-static.net/uploads/4373983/normal_6011f5da5eabd.pdf
    • http://gubixazolela.sportsontheweb.net/practice_writing_chinese_characters.pdf
    • https://cdn-cms.f-static.net/uploads/4482027/normal_6036b59c9937b.pdf
    • http://gadetebes.sportsontheweb.net/hellboy_comics_download.pdf
    • https://cdn-cms.f-static.net/uploads/4414156/normal_60192fe8611bd.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/bipovoromoj/what_does_the_mind_control_ray_do_outer_worlds.pdf
    • https://s3.amazonaws.com/gajabedafot/letters_coloring_worksheet.pdf
    • http://kegigija.atwebpages.com/paximixukedodutate.pdf
    • http://xusapibu.onlinewebshop.net/77661303879.pdf
    • https://s3.amazonaws.com/libosokune/dolur.pdf
    • https://s3.amazonaws.com/xabalaru/10103806848.pdf
    • https://f11c4bf2-12a6-49f8-9590-07a94b689168.filesusr.com/ugd/11276f_e2cac5fde2de4a508b15b7b73eaf2215.pdf?index=true
    • http://jalijoruki.atwebpages.com/polygamy_in_christianity.pdf
    • https://8a89c5bc-485b-4808-980c-66c60e8d9908.filesusr.com/ugd/834936_310f19ff1a754183a9da0347e25a8365.pdf?index=true
    • https://s3.amazonaws.com/zerepuzuze/how_to_calculate_width_and_height_css.pdf
    • https://s3.amazonaws.com/gezejoputiwinu/myocardial_infarction_guidelines_australia.pdf
    • http://zaxuzut.atwebpages.com/74842320989.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f16a.bin
7cc270f5613cc0c2fe7cc998de0a6bb55262fa2716d5efe81c0f27e67fa42db9
pdf-font-stream PDF embedded font (sfnt) at offset 0xF16A 5012 bytes
font_01_sfnt_off00010242.bin
3e7cdac703b4d3fa16275ffe641cd97c9780dd4ffd53c03e5cd091c6399411db
pdf-font-stream PDF embedded font (sfnt) at offset 0x10242 11304 bytes
font_02_sfnt_off000127b5.bin
7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0x127B5 4324 bytes