Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d3ef75ab94e4ada…

MALICIOUS

PDF

75.2 KB Created: 2021-04-03 14:59:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ed6a6a9722cf9c9c30819869a6710459 SHA-1: 296b681b8c3a0cb41a8da1779b1b6739fe724989 SHA-256: 7d3ef75ab94e4ada565d7c4093e94e747a6ed9d6a1d983ec6ba0a2b32a3afc52
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many of which are SEO-themed, suggesting an attempt to drive traffic to potentially malicious sites. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded links are indicative of a malicious document designed to exploit users through deceptive content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=ms+sharepoint+2013+user+guide
    • http://apkweb.net/which_of_the_following_is_not_a_suitable_assignment_statementoum9a.pdf
    • https://cdn.sqhk.co/sovokeduseb/ijwRicR/candlestick_explained.pdf
    • https://cdn.sqhk.co/fafojipedul/UKWhghf/red_balloon_movie_youtube.pdf
    • https://linepapimufuto.weebly.com/uploads/1/3/1/6/131637640/e8397e634ef.pdf
    • https://cdn.sqhk.co/wemorapi/eUqGeT1/chess_tactics_in_slav_defense.pdf
    • https://nujuwededewomoj.weebly.com/uploads/1/3/4/3/134305400/5138863.pdf
    • http://rocketdocs.us/95454802165caee1.pdf
    • http://microbestdigitalmeter.xyz/41821570410n3o49.pdf
    • https://cdn.sqhk.co/numokafas/ijiiice/menalegofuka.pdf
    • http://my-favshopf.online/46954271360agjtn.pdf
    • https://tarezusubem.weebly.com/uploads/1/3/5/3/135386237/093a3e0c03f58e1.pdf
    • https://serekarivevug.weebly.com/uploads/1/3/1/4/131407867/tuzotulup_warasumupatifo.pdf
    • https://wiruwopifezub.weebly.com/uploads/1/3/4/3/134345133/pamezoku.pdf
    • http://cashbackk.site/315390841584mfi5.pdf
    • https://cdn.sqhk.co/lilaxikixo/xbfMrjj/chikki_meaning_in_tamil.pdf
    • http:///������$fieldXml
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/pipaneku/ark_survival_evolved_android_game_free.pdf
    • https://uploads.strikinglycdn.com/files/44340946-c7e5-4fc9-93fe-359cc7f7ab77/taming_of_the_shrew_act_1_important_quotes.pdf
    • https://uploads.strikinglycdn.com/files/70b9145e-cd18-4a9b-970d-a601aa5f043d/jvc_kd-sr40_usb_cannot_play.pdf
    • https://s3.amazonaws.com/sinamozagemoger/sulopolegujijexavode.pdf
    • https://s3.amazonaws.com/bisute/38966984018.pdf
    • https://uploads.strikinglycdn.com/files/cc352abd-d8ba-4467-ac8b-eebaa876d4b2/balosowinatugalu.pdf
    • https://s3.amazonaws.com/vavabi/bose_wave_radio_bluetooth_adapter_manual.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e708.bin
74915434114c38420c22c70ec3c8183e2d0d864785f6b9dccce3f7063a051ff9
pdf-font-stream PDF embedded font (sfnt) at offset 0xE708 5684 bytes
font_01_sfnt_off0000fa64.bin
a4aa685ccf2de021762bd889bac2e29c4ed53f36fbcf4e381dea69225c6f241a
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA64 10824 bytes