Malicious PDF — malware analysis report

Static analysis result for SHA-256 646e2d00c8da4826…

MALICIOUS

PDF

84.7 KB Created: 2021-03-21 00:02:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: be235c9d5558b473649a3acddc2081fa SHA-1: 6c64bcf8115402c4c120bb98b28c63a7326cf2cf SHA-256: 646e2d00c8da482642f80b5fadfe0ed719c575e9e65b8091b792605e3a0249c3
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious and phishing-related. It contains a large number of external links, with one suspicious URL pointing to 'ponafet.ru'. Although no scripts were explicitly extracted, the PDF structure and the presence of numerous links suggest an attempt to redirect users to malicious content, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/wix?keyword=bose+acoustimass+5+series+ii+review
    • https://cdn.sqhk.co/mogezunir/giLjcjb/29661068360.pdf
    • https://cdn.sqhk.co/budajawisore/5jigghi/80307330555.pdf
    • https://cdn.sqhk.co/peposusuwi/iggibig/16868735663.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://6632aaff-1fe9-4f1d-acb3-7d444e457837.filesusr.com/ugd/ce4b7c_7d39c118fd0c43c4bac35df7c37a5ce7.pdf?index=true
    • https://uploads.strikinglycdn.com/files/5c54859a-24d1-41bd-8ae0-67787e469f32/algorithm_design_manual_solutions_github.pdf
    • https://s3.amazonaws.com/xefezesebusu/45740934701.pdf
    • https://uploads.strikinglycdn.com/files/8f645683-28e6-48a4-a239-319054fdfbba/mbti_types_anime_characters.pdf
    • https://7f58a6d3-5723-489e-a2bd-17fd91e1ddd5.filesusr.com/ugd/655495_e30a1e20f0cf473fb64228883c0ba49a.pdf?index=true
    • https://uploads.strikinglycdn.com/files/36127ed7-227c-423b-b57a-537f413e9fb7/how_to_replace_battery_chamberlain_garage_door_openers.pdf
    • https://uploads.strikinglycdn.com/files/42e28859-5278-410d-8db6-2d927ea17457/kitchenaid_food_processor_attachment.pdf
    • https://s3.amazonaws.com/sisaxu/locking_specific_cells_in_excel_sheet.pdf
    • https://4edd92ed-4e96-4c3d-a837-a16c7246ae9e.filesusr.com/ugd/7c3149_ff90b55e78c2432fa6534752faf024b1.pdf?index=true
    • https://uploads.strikinglycdn.com/files/05e37890-879c-48b5-bcf7-ba5bba22c304/keurig_k65_water_reservoir.pdf
    • https://uploads.strikinglycdn.com/files/23f5cda2-7727-4921-b1a1-83b7161f5490/59953354717.pdf
    • https://uploads.strikinglycdn.com/files/b8f8ed58-a233-4f65-90ae-a214dcaf2566/39305303661.pdf
    • https://s3.amazonaws.com/liwafo/journal_of_thermal_analysis_and_calorimetry_template.pdf
    • https://uploads.strikinglycdn.com/files/46ef2932-d230-4f25-b612-6f648330511e/82801461182.pdf
    • https://uploads.strikinglycdn.com/files/cbc69dc0-6c2a-4e9b-9125-680da179548f/2008_yamaha_v_star_1100_classic_service_manual.pdf
    • https://s3.amazonaws.com/limewub/vuwaramobawoluj.pdf
    • https://uploads.strikinglycdn.com/files/4bb522f5-795d-4804-8906-fb6a1a11fdb6/what_is_the_difference_between_nevertheless_and_however.pdf
    • https://s3.amazonaws.com/vexeliku/kiteboarding_buyers_guide.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000edd5.bin
30c74f36167edd8abae00358bbebd0175de67f3d7c796822b314f9efb0b8e20c
pdf-font-stream PDF embedded font (sfnt) at offset 0xEDD5 8696 bytes
font_01_sfnt_off00010b0b.bin
57bfc5af8a544210243d7fd4f932d87c800c6ab4b5d91f835c6cfd6152685d91
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B0B 5240 bytes
font_02_sfnt_off00011cdd.bin
fa7e4be19832746ac168fe8778f0178574c9b7f9534f3265e7465e22279f8573
pdf-font-stream PDF embedded font (sfnt) at offset 0x11CDD 11320 bytes