Malicious PDF — malware analysis report

Static analysis result for SHA-256 71718f391811a2f1…

MALICIOUS

PDF

78.0 KB Created: 2021-03-27 14:52:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a2c59a4f36a438cdfdbb00c7a003e628 SHA-1: 1a39e86f36e0fcc55b081277e9a4372b575fc643 SHA-256: 71718f391811a2f1395e60bf6edf02d3120439982ad4dc4406fb8a4763602888
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a phishing and potential trojan threat. It contains a large number of external links, suggesting a link farm designed to distribute malicious content. The document body, though heavily obfuscated, appears to be a lure related to 'Adobe indesign cc tutorial pdf free download', aiming to trick users into clicking on malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=adobe+indesign+cc+tutorial+pdf+free+download
    • http://jamotovoxut.mywebcommunity.org/80026932298.pdf
    • http://jujavekerubeko.scienceontheweb.net/natizuferipirowedaja.pdf
    • https://cdn.sqhk.co/dabebasavus/0Ajijai/76854499223.pdf
    • http://gazajujana.mygamesonline.org/41968995543.pdf
    • https://cdn.sqhk.co/bexefoboxevi/hj01dZo/major_mayhem_2_apk_hack_download.pdf
    • http://xofitazuregokud.mywebcommunity.org/ordinal_numbers_and_dates_worksheet.pdf
    • https://cdn.sqhk.co/tixunadegu/HjbTIii/liwolunenogujodupiki.pdf
    • http://pekefosijemibi.sportsontheweb.net/website_analysis_report.pdf
    • http://rimujitibux.mypressonline.com/a_level_maths_notes_edexcel.pdf
    • https://cdn.sqhk.co/lewivapawo/dujahgC/6260176141.pdf
    • http://lalevuw.mypressonline.com/jiseno.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://7a69a04d-b0b3-478e-a927-895b34d3dd44.filesusr.com/ugd/159848_fb5984a3bedc423ab89da18612a6bb80.pdf?index=true
    • https://85d2c5a2-fc31-4f76-86b4-4ebe2abe2bf4.filesusr.com/ugd/a8cc01_ac7a8ee3ba6447e7816cb1024a9d1b79.pdf?index=true
    • https://c7fb3737-a2fb-4e06-b71d-f78b648bb0a4.filesusr.com/ugd/a9248e_96b63984c12b48728bed9da838ff5f83.pdf?index=true
    • https://dc383e6d-b7a3-4e67-a88a-227fa542b6c3.filesusr.com/ugd/72b0e7_b8ac85429108420a807c67c683d8f781.pdf?index=true
    • https://8de17e8c-b43d-4143-985d-773a0aa332b1.filesusr.com/ugd/01f6ad_f5b65a9fc13f454a906d23887dd85c3b.pdf?index=true
    • https://8eeb1f0a-0cdd-4c66-98a4-83777b49fb54.filesusr.com/ugd/64f9d2_8a38a00e5f8844948d972dc7506b502b.pdf?index=true
    • https://748f1d53-d141-46c1-926a-d14fc69713a3.filesusr.com/ugd/e3ed1f_9b211459413f4f15920272af44a97916.pdf?index=true
    • https://7d33af4c-acfd-4996-9436-348e89828b5b.filesusr.com/ugd/289672_49a260886ca544f689b7b3d63da956f1.pdf?index=true
    • https://a5fc3680-5c08-4cda-bd6c-abaa3bdf25bc.filesusr.com/ugd/ea5d7b_1577a7178eda4ea3a4c38756cf61117a.pdf?index=true
    • https://7f993087-45f6-41f4-96e5-9dcaca18fb91.filesusr.com/ugd/9a92dd_5535d78794564363b176356789e1736c.pdf?index=true
    • https://85377554-d84f-42a6-a955-c87f7d5d3d8c.filesusr.com/ugd/dd4472_8cafebd5b1a04b289f6bd4da7beabe5e.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f027.bin
0f48fdf27887bbac96bb01b32602e94b6d990e503ffe814adc6d29195b842fa2
pdf-font-stream PDF embedded font (sfnt) at offset 0xF027 5544 bytes
font_01_sfnt_off00010322.bin
db4613b4d134dd64e7eb9b09f4daef4a25a54c515d0cf2ca452dc3e1d974a6a7
pdf-font-stream PDF embedded font (sfnt) at offset 0x10322 11004 bytes