Malicious PDF — malware analysis report

Static analysis result for SHA-256 6820b4b12ad6bc8f…

MALICIOUS

PDF

87.7 KB Created: 2021-03-23 21:06:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c2a661e6737c4ceca2f57ee9a49eab85 SHA-1: 977ea3f6b1b9a5d8e16c1b4547bd650ee7a521d2 SHA-256: 6820b4b12ad6bc8f0cf45c60f26214d2e9893231dfa81a31c5ff031eba9f0fc3
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, suggesting a phishing or SEO manipulation tactic. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were directly extracted, the PDF structure and embedded URLs point towards a malicious document designed to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=sylvia+plath+daddy+review
    • https://xorataseturife.weebly.com/uploads/1/3/5/3/135333409/mimefowugob-misibife-diloxax-wevoz.pdf
    • http://bobujopolodusol.mygamesonline.org/xutokoninegevuvusaniso.pdf
    • https://dovizitozul.weebly.com/uploads/1/3/1/4/131408131/8461817.pdf
    • https://cdn.sqhk.co/difixoruze/LKTrief/rally_championship_gamecube_rom.pdf
    • https://cdn.sqhk.co/ruzesowasu/8Rxhdhf/wozofivekimuwuw.pdf
    • https://cdn.sqhk.co/fidinananale/iaIiaid/netibamoxuvudugokaxar.pdf
    • https://cdn.sqhk.co/ruzixamover/O6zji8q/podesevekofagozeda.pdf
    • https://cdn.sqhk.co/fafopikej/laFAcH4/4241646673.pdf
    • http://huaweistoreukr.xyz/how_to_do_a_preparation_outline_for_a_speechbifrj.pdf
    • https://sutowuvo.weebly.com/uploads/1/3/4/6/134685384/benumuxer_mekos.pdf
    • https://cdn.sqhk.co/toxodimina/9gigfPc/fenafuwoxeji.pdf
    • http://storeyou.store/modern_money_mechanics_zeitgeistikuq7.pdf
    • https://cdn.sqhk.co/zarifabidit/gchiQjd/25819968634.pdf
    • https://cdn.sqhk.co/sututidogo/gd8Ojec/climbing_away_spain.pdf
    • http://idealslimitalia-ufficiale.site/concepto_de_salud_publica_omsgq021.pdf
    • http://tiwimifozukimu.medianewsonline.com/49813246520.pdf
    • https://cdn.sqhk.co/nenutipu/icvfjej/zemij.pdf
    • https://cdn.sqhk.co/ledodatefu/fqgcjf8/color_fill_icon_png.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://naburonip.myartsonline.com/65633668768.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011a6f.bin
8684216c75b5e26381e1584e7073b04bbc4aeba6f900e9b69dabb0a5aba3caed
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A6F 5224 bytes
font_01_sfnt_off00012c48.bin
0791c15beeab5ecdc41302afa9505eac27c4390cc8d885be70faaf4adc5937fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x12C48 11040 bytes