Malicious PDF — malware analysis report

Static analysis result for SHA-256 6961fb735fd459bd…

MALICIOUS

PDF

65.3 KB Created: 2020-11-24 14:18:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4988bafa661c516ae9ad7c882c5a62b6 SHA-1: cb9f22f94823dddf3a4f0a5419b45b8bf727a917 SHA-256: 6961fb735fd459bd4e4d823f9154733907e579f0209a16b19184f55bef77c302
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded URLs and heuristics indicate it functions as a link farm on disposable hosting, with one URL specifically mentioning 'indiana state university financial aid forms' to deceive the user. The ML classifier and ClamAV detection strongly suggest malicious intent, likely phishing or malware distribution via the linked content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/aws?utm_term=indiana+state+university+financial+aid+forms
    • https://rutijafajiwep.weebly.com/uploads/1/3/4/5/134592903/vadomaje-falis-rujexipi-boxik.pdf
    • https://nizovekakajet.weebly.com/uploads/1/3/4/7/134740669/tusideboki.pdf
    • https://fisalusul.weebly.com/uploads/1/3/4/3/134341538/ad4ed5dfc8376e.pdf
    • https://sawalodisixujig.weebly.com/uploads/1/3/4/4/134490012/5ac8baf3338d.pdf
    • https://cdn-cms.f-static.net/uploads/4412773/normal_5f93b20caea75.pdf
    • https://faworufobideped.weebly.com/uploads/1/3/2/6/132682851/puwoxopi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/varoximu/alfabeto_griego_pronunciacion.pdf
    • https://s3.amazonaws.com/sugaguxagu/2126517257.pdf
    • https://s3.amazonaws.com/dukexajuj/zabun.pdf
    • https://uploads.strikinglycdn.com/files/9f67c8df-8e43-444e-835d-143caf2c9091/kakutonuwopesuf.pdf
    • https://uploads.strikinglycdn.com/files/c13496f3-dbfe-46ea-b061-66ca8c071ea8/5._snf_trke_soru_bankas.pdf
    • https://s3.amazonaws.com/jewizopukuni/84741123162.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c3c3.bin
d4ba9d053060400b971998c84c060be1da3f59ac2f1b67f91f89c1c6bcd4903b
pdf-font-stream PDF embedded font (sfnt) at offset 0xC3C3 5268 bytes
font_01_sfnt_off0000d5aa.bin
74b164920d99541f3e48b74ca4caa0432705202a8a59dcdeaee08bb44e44f1b9
pdf-font-stream PDF embedded font (sfnt) at offset 0xD5AA 10148 bytes