Malicious PDF — malware analysis report

Static analysis result for SHA-256 6538c26b8289dfab…

MALICIOUS

PDF

79.9 KB Created: 2021-06-01 07:17:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6a8615979dcce182a6c3c1707d170d76 SHA-1: 16fd06a4f5fd6345d9b20907d4096544c68d62b5 SHA-256: 6538c26b8289dfab925d5b29a98ba13d1d9951fc78a7b9496c7d2d9f6ce671a2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many pointing to `pbworks.com` and `weebly.com` domains, suggesting a link farm or SEO manipulation tactic. The primary URL, `https://huntic.ru/pbw?utm_term=food+for+heartburn+relief+during+pregnancy`, is presented as a search result, indicating a phishing or scam lure. ClamAV detection and ML classification strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://huntic.ru/pbw?utm_term=food+for+heartburn+relief+during+pregnancy
    • https://lamonide.weebly.com/uploads/1/3/4/0/134096931/9122100.pdf
    • https://kuzeposevitisol.weebly.com/uploads/1/3/4/8/134881899/dexona.pdf
    • https://senevabitup.weebly.com/uploads/1/3/4/2/134234896/xajinomonil.pdf
    • https://xitozenajoxoge.weebly.com/uploads/1/3/2/6/132681812/022e5387a.pdf
    • https://wajativakol.weebly.com/uploads/1/3/4/7/134749030/319b1.pdf
    • https://jomaredavox.weebly.com/uploads/1/3/2/3/132302995/xelezagawive_dufoxijijilanat.pdf
    • https://lelibajoterudu.weebly.com/uploads/1/3/4/0/134042739/matovezimiwivemijumi.pdf
    • https://wekexobesunolo.weebly.com/uploads/1/3/0/7/130739288/julipatuzowod_jonovavam.pdf
    • https://xajasobuz.weebly.com/uploads/1/3/4/8/134861619/24cf007e5.pdf
    • https://larebefol.weebly.com/uploads/1/3/4/6/134691273/b60f3facc.pdf
    • https://gavivexov.weebly.com/uploads/1/3/4/6/134667590/5503844.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://vadibun.pbworks.com/f/44455790463.pdf
    • http://zeladejan.pbworks.com/f/30050319288.pdf
    • http://bupataved.pbworks.com/f/halloween_cat_face_paint_easy.pdf
    • http://bupataved.pbworks.com/f/jebumebofa.pdf
    • http://rugewenuzed.pbworks.com/w/file/fetch/144423462/buvirixu.pdf
    • https://uploads.strikinglycdn.com/files/becc1c13-6d45-45d3-a40b-79f4c65bb206/biology_corner_dna_replication_coloring_worksheet_answer_key.pdf
    • https://uploads.strikinglycdn.com/files/3c0034ec-a892-4018-97be-648757d8d6cf/wafadej.pdf
    • https://uploads.strikinglycdn.com/files/239743a6-4666-4a5e-8927-f446fa718b3b/matufej.pdf
    • http://gatasulupu.pbworks.com/f/change_32_bit_to_64_bit_windows_8.pdf
    • http://rugewenuzed.pbworks.com/w/file/fetch/144423456/88044860200.pdf
    • https://uploads.strikinglycdn.com/files/bd167a3d-968a-4e37-9e17-c5e08b189e61/acorde_si_m_piano.pdf
    • http://pamotekegopa.pbworks.com/f/bose_soundlink_colour_firmware_update.pdf
    • https://uploads.strikinglycdn.com/files/70a42948-113e-4f5e-9bc5-96faf896978d/araby_name_meaning.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ecda.bin
2ba0d326cda69558445554f1437f7d93278c9ac43a987e72d322e93ee1eb81fa
pdf-font-stream PDF embedded font (sfnt) at offset 0xECDA 5320 bytes
font_01_sfnt_off0000fef0.bin
597a1930064cd9b968322d391bcb20793ea893ef19a4632431da7ebb1d78ab92
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEF0 10716 bytes
font_02_sfnt_off00012392.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x12392 4324 bytes