Malicious PDF — malware analysis report

Static analysis result for SHA-256 73ed61c3d331db88…

MALICIOUS

PDF

119.3 KB Created: 2021-05-30 03:19:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c2cbfe21404bf21da33f0b710f0a42bc SHA-1: 7edd240b8c5412798a0e47941a18f837103b3e0a SHA-256: 73ed61c3d331db883a0ed8f2a0daece7fbbf13344e52844fb0510e165f7ec385
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, which is a common tactic for phishing or distributing further malware. The ClamAV detection and ML classifier strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URLs suggest it's designed to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=char+broil+big+easy+electric+smoker+instructions+manual
    • https://static.s123-cdn-static.com/uploads/4376371/normal_5fcc93f7cf22f.pdf
    • https://nusomosuguxapo.weebly.com/uploads/1/3/4/6/134693055/1b4d6347eae5.pdf
    • https://linajijokib.weebly.com/uploads/1/3/4/0/134000065/dakoti-kixusikomeb-zaberipab-zisevuno.pdf
    • https://static.s123-cdn-static.com/uploads/4464874/normal_5ff23159ccc4e.pdf
    • https://cdn-cms.f-static.net/uploads/4389821/normal_5fd6e7a22d6ac.pdf
    • https://cdn-cms.f-static.net/uploads/4479710/normal_5fd6007564458.pdf
    • https://gavatuwideziwi.weebly.com/uploads/1/3/4/3/134352821/9628968.pdf
    • https://vekazapez.weebly.com/uploads/1/3/4/6/134601327/vugolatel.pdf
    • https://cdn-cms.f-static.net/uploads/4452852/normal_603c46b223cce.pdf
    • https://cdn-cms.f-static.net/uploads/4492240/normal_602e4c4093047.pdf
    • https://vumevomuw.weebly.com/uploads/1/3/4/3/134335884/c0c1a58a89130.pdf
    • https://cdn-cms.f-static.net/uploads/4491153/normal_602edecb381c2.pdf
    • https://bekefopu.weebly.com/uploads/1/3/4/6/134692172/bovigolajadibomo.pdf
    • https://cdn-cms.f-static.net/uploads/4366995/normal_602428c6b0478.pdf
    • https://cdn-cms.f-static.net/uploads/4501028/normal_60696c09c09bc.pdf
    • https://cdn-cms.f-static.net/uploads/4465010/normal_60138ddf229c6.pdf
    • https://cdn-cms.f-static.net/uploads/4488139/normal_60513bcfca9d1.pdf
    • https://cdn-cms.f-static.net/uploads/4409243/normal_600e3c2b26dd5.pdf
    • https://tazokadenu.weebly.com/uploads/1/3/2/6/132695553/7589353.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/9dc3c965-0bb3-48d4-952e-ad454f6870a1/on_the_sidewalk_bleeding_evan_hunter_analysis.pdf
    • https://uploads.strikinglycdn.com/files/8bcdbeeb-b81f-4965-abbb-1d5e6a5f3a24/how_to_sew_a_hot_dog_pillowcase.pdf
    • https://uploads.strikinglycdn.com/files/dc551312-2f5c-4e73-9a9a-57387b7f0401/zemoweminafefanaluxusoke.pdf
    • https://uploads.strikinglycdn.com/files/377b16d2-115e-4ee7-b219-96a97ff55d89/best_miele_canister_vacuum_for_the_money.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018433.bin
df42635b0be584725326f8f459f13410ce6d69fc442bebd6f26e810419207e5c
pdf-font-stream PDF embedded font (sfnt) at offset 0x18433 5424 bytes
font_01_sfnt_off00019680.bin
fa3c0c75cf0f3dd3bb592a152c14ce484baa81ed3077cca5963b0d4f732a2b9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x19680 2116 bytes
font_02_sfnt_off00019fad.bin
a45d256d2f4bfb39c1ac6de059b5641700fa4ec43bed8d6ad8032435c8cf2832
pdf-font-stream PDF embedded font (sfnt) at offset 0x19FAD 15044 bytes