Malicious PDF — malware analysis report

Static analysis result for SHA-256 6533f7de3c67d36f…

MALICIOUS

PDF

115.3 KB Created: 2021-01-14 20:41:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-12
MD5: 4b44619aa553963ab1df0660f83bc4da SHA-1: 6ac9dbd64bda2e15de1f8ce9bd71b611db52e685 SHA-256: 6533f7de3c67d36f22fb20d98cbfc8c1d9fd734cc9eccb2458df497dfd72f7aa
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to redirector infrastructure and a link farm. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically phishing or malware distribution. The embedded URLs are the primary indicators of compromise, facilitating the redirection to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9909

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/123?utm_term=what+does+corroboration+mean+in+spanish In PDF document text
    • https://cdn.sqhk.co/lapefuxolu/hjDihib/69103972966.pdfIn PDF document text
    • https://nunesevafarub.weebly.com/uploads/1/3/0/8/130874378/734dcdd.pdfIn PDF document text
    • https://site-1177018.mozfiles.com/files/1177018/trending_news_videos_today.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4415081/normal_5fd6107659cfb.pdfIn PDF document text
    • https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/wedit_bajojabo.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4389568/normal_5fd1a03c93447.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • https://s3.amazonaws.com/sesijesule/reform_cantorial_school.pdfIn PDF document text
    • https://s3.amazonaws.com/fewunadupop/indian_army_soldier_hd_photos.pdfIn PDF document text
    • https://s3.amazonaws.com/zalomi/97930516781.pdfIn PDF document text
    • https://s3.amazonaws.com/sefukirexuwekij/net_framework_2._0_5027_free.pdfIn PDF document text
    • https://s3.amazonaws.com/jidagafinuxesu/shop_rental_agreement_format_in_tamil.pdfIn PDF document text
    • https://s3.amazonaws.com/benubapopikaj/52694942334.pdfIn PDF document text
    • https://s3.amazonaws.com/zugutixe/pagibe.pdfIn PDF document text
    • https://s3.amazonaws.com/xoxaneral/alesis_vi61_editor_manual.pdfIn PDF document text
    • https://s3.amazonaws.com/fidefofudi/pezifipanupotipufogagega.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_010_off00017a7b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x17A7B 28404 bytes
SHA-256: 24234ebe9323c416ea8679d3257a76a26d0a5822b9b80ae41ce06ef9426136da
font_00_sfnt_off0000f0a1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF0A1 5684 bytes
SHA-256: 0570c57cc5aff57312960fd92c102d83273e7447f5a4496501d382b26a2efd99
font_01_sfnt_off00010473.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10473 5432 bytes
SHA-256: 81ddb3d438dd5479e93d229fb9b9047ff4132bcba853a372aa38c14908d1312c
font_02_sfnt_off000116bf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x116BF 2656 bytes
SHA-256: 1620336da6018abf771a3b64a4739dbc5cc5761e5bcfd31f9568e9163b5e6178
font_03_sfnt_off000121c6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x121C6 2328 bytes
SHA-256: 6d897259d7ab9db79b0dbb16904cd99ff486aa7f4a475590a5d3e44eab6e0eed
font_04_sfnt_off00012c7c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12C7C 2108 bytes
SHA-256: b3976ad28991401f3a7e0d936621f3963ed8fd81aff5bedc9e25cf6548b1959b
font_05_sfnt_off00013647.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13647 6640 bytes
SHA-256: c8cb303e765c67f43d6d34f29c1d02953890772ff7b697be779fb29335000f72
font_06_sfnt_off000147e6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x147E6 16912 bytes
SHA-256: 27595d12c9d6694359b231f683e8e4306976143a5d6d72f7f34fca1dc82441df
font_08_sfnt_off0001ae2b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1AE2B 3276 bytes
SHA-256: 333cf0bae5291019b79d77a37696b89786718dc77a0e6f1c7356514a48765311