Malicious PDF — malware analysis report

Static analysis result for SHA-256 5afa5c726c59ab89…

MALICIOUS

PDF

71.9 KB Created: 2021-06-02 02:41:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8d1304f3f02a3d44c094271e1e65a662 SHA-1: e73f37f94ba5c24e07c16f18d8f23e183c9073d9 SHA-256: 5afa5c726c59ab894555ea4396337b7aa5968019d01452bed4ff3f3cd1506e2f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, identified as a link farm, with one prominent URL pointing to a page related to a deceased classmate's funeral. This suggests a social engineering tactic to entice users to click. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8129

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://queure.ru/pbw?utm_term=deceased+classmate+funeral+resolution+for+a+classmate
    • https://cdn-cms.f-static.net/uploads/4406785/normal_5fdae8ec38799.pdf
    • https://static.s123-cdn-static-d.com/uploads/4408993/normal_60b3b8bb1cf8a.pdf
    • https://vanunogagasibe.weebly.com/uploads/1/3/5/9/135964710/0cbd5.pdf
    • https://cdn-cms.f-static.net/uploads/4496585/normal_6046f10675b32.pdf
    • https://sirukume.weebly.com/uploads/1/3/0/8/130814715/65b67adc20187e.pdf
    • https://sixanatol.weebly.com/uploads/1/3/4/6/134631849/zopatafusibudew.pdf
    • https://static.s123-cdn-static.com/uploads/4373788/normal_5ffc7b5c460fa.pdf
    • https://cdn-cms.f-static.net/uploads/4477408/normal_602d3f6dc9c67.pdf
    • https://static.s123-cdn-static.com/uploads/4384145/normal_5ff474b6379f3.pdf
    • https://static.s123-cdn-static.com/uploads/4478125/normal_5fcd5ff5011fa.pdf
    • https://static.s123-cdn-static.com/uploads/4476274/normal_5ffebeb1c8f33.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/48f4539b-8438-4640-a07b-37255bd75c5a/nisexizanofuzav.pdf
    • https://uploads.strikinglycdn.com/files/d50ba943-ca4e-41a2-899c-98026f272201/hp_designjet_500_42_inch_trailing_cable.pdf
    • http://tisowowuduwe.pbworks.com/f/bally_5000_plus_slot_machine_manual.pdf
    • https://uploads.strikinglycdn.com/files/a0eff92d-5142-4f73-a1a6-9a7e382e4abb/duvarlarin_dili_olsa_2_turkce_dublaj_izle.pdf
    • http://wojipag.pbworks.com/w/file/fetch/144413640/24103315903.pdf
    • http://dipoziw.pbworks.com/f/33543404485.pdf
    • https://uploads.strikinglycdn.com/files/80a3b8e5-2f8a-41a4-a49a-300249389110/el_monstruo_de_colores_actividades_preescolar.pdf
    • http://sipibujewadu.pbworks.com/w/file/fetch/144483546/download_plants_vs_zombies_2_hack_cho_ios.pdf
    • https://uploads.strikinglycdn.com/files/772bf9be-1b86-4e9c-b845-2685c378f1a0/25528539168.pdf
    • https://uploads.strikinglycdn.com/files/e6d36a6b-9136-40ea-9580-dac8280ec0fd/lejimitatowuzobib.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f77e.bin
e64c8a037b6fdc8915b942d17bcebe64aa8ee5e826c52793c917febadc6fe8f2
pdf-font-stream PDF embedded font (sfnt) at offset 0xF77E 5168 bytes