Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b81492870166280…

MALICIOUS

PDF

66.1 KB Created: 2020-11-10 07:51:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: aae2dfaae24e297f8d7b90e3f301cc90 SHA-1: 1796776fb47584cd570f1ffae451584e3b83bd43 SHA-256: 6b81492870166280312be11e997cdee6ae326a07df0875bbf1b381afdbb1bc02
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many pointing to PDF files, suggesting a link farm or redirection to malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and heuristic firings point towards a phishing or malware distribution attempt, likely leveraging embedded JavaScript to facilitate redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/123?keyword=enzyme+concept+map+worksheet
    • https://xufiwelak.weebly.com/uploads/1/3/1/1/131164558/9b9fcbb3dcbeaab.pdf
    • https://jimagofer.weebly.com/uploads/1/3/0/8/130813953/b157112afd08a.pdf
    • https://kilutiwoxit.weebly.com/uploads/1/3/1/6/131636983/2110de94cc2cf1.pdf
    • https://kavivapepegag.weebly.com/uploads/1/3/4/2/134235540/f023dd2.pdf
    • https://ronesafoko.weebly.com/uploads/1/3/4/3/134312324/6243981.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/henghuili-files2/fasobobilogimegikagewa.pdf
    • https://uploads.strikinglycdn.com/files/8c154c77-a4cf-486e-ac3b-07bdce7d771f/17403933383.pdf
    • https://uploads.strikinglycdn.com/files/dc5aa03f-916a-4e20-a344-0bc018d0d0a0/stoichiometry_worksheet.pdf
    • https://uploads.strikinglycdn.com/files/afdb803c-d02d-46c6-9d68-be5c813ecd78/infinity_apk_android_tv.pdf
    • https://s3.amazonaws.com/jezaxojipevu/6th_to_10th_book_back_questions_and_answers_download.pdf
    • https://uploads.strikinglycdn.com/files/49c80f8b-7939-4b31-880b-b14559875faa/9162013965.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c69b.bin
435b6f93340ffb9ff78bafd448a46dd4acc6b4324f549daa23a0a2734e004327
pdf-font-stream PDF embedded font (sfnt) at offset 0xC69B 5404 bytes
font_01_sfnt_off0000d8fc.bin
62e687a86627f8c72a2af2ed1e432af010fd1a2fb974c0368a613c87694ed170
pdf-font-stream PDF embedded font (sfnt) at offset 0xD8FC 10168 bytes