Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d4b3d0b676da260…

MALICIOUS

PDF

70.4 KB Created: 2021-01-24 10:32:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 94e33ed87791be97b76a1e507666df6d SHA-1: ea544c8819c72643fadb0908db8a9e37757b6cdf SHA-256: 7d4b3d0b676da260ff026ea6b50c66f0adeb1b37a3a59d548fa24f4a2ea0086a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which point to PDFs hosted on various domains, suggesting a link farm or SEO manipulation tactic. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and the presence of numerous external URIs are indicative of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/aws?utm_term=cfp+championship+2019+halftime+show+performers
    • https://static.s123-cdn-static.com/uploads/4387709/normal_5fdef4b84686d.pdf
    • https://static.s123-cdn-static.com/uploads/4370090/normal_5fe39f0a254c9.pdf
    • https://static.s123-cdn-static.com/uploads/4449604/normal_5feefc71403aa.pdf
    • https://static.s123-cdn-static.com/uploads/4411512/normal_5fceaca17e0a1.pdf
    • https://xuwumiguxapizif.weebly.com/uploads/1/3/0/7/130739656/boluvuliluzepabum.pdf
    • http://momijuluxesapek.iblogger.org/cdsco_guidelines_for_clinical_trials.pdf
    • https://static.s123-cdn-static.com/uploads/4374540/normal_6000419971dae.pdf
    • https://static.s123-cdn-static.com/uploads/4401517/normal_5fe55543d985b.pdf
    • https://nozijuga.weebly.com/uploads/1/3/4/6/134698325/puduvamoji-sovanusasizofeb-dalomawi-madifexuw.pdf
    • https://givadebar.weebly.com/uploads/1/3/1/4/131437750/xelaf-tusaxasov-pekejudimumapi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://belukamafanes.rf.gd/analog_and_digital_communication_book_free.pdf
    • http://xumerapugegivo.epizy.com/visawixomemaki.pdf
    • http://virefixifefuke.epizy.com/training_feedback_form_template_word.pdf
    • http://xisapedugifado.epizy.com/75776947292.pdf
    • http://fepadegan.epizy.com/autumn_leaves_ielts_reading_answer_key.pdf
    • http://gogolozumer.epizy.com/levis_uk_womens_size_guide.pdf
    • http://bugifub.epizy.com/52444596404.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d3a5.bin
975d41af5949e79ca128112a51772447d760dbb1279d487ddcd56045611dcb35
pdf-font-stream PDF embedded font (sfnt) at offset 0xD3A5 5732 bytes
font_01_sfnt_off0000e715.bin
c636af5d2aa1c87c2040393e6afab1aad18b95964058169cddbac806a322db8e
pdf-font-stream PDF embedded font (sfnt) at offset 0xE715 10952 bytes