Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e484bc6f954d2a4…

MALICIOUS

PDF

80.6 KB Created: 2021-03-24 20:00:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f433c3d7da6267c1ffb12e1c6d3f0b12 SHA-1: d3e1a7ef7e89b5a6d0b497989a8696fca8e42598 SHA-256: 7e484bc6f954d2a405f931ef33bf8b1fdd9194722d21e786fecd23e0acc29c88
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, suggesting a phishing or SEO poisoning attempt. The ClamAV detection and ML classifier strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous external URLs point towards an attempt to redirect users to malicious content, likely for further exploitation or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=mtg+physics+today+pdf+download
    • https://cdn-cms.f-static.net/uploads/4406202/normal_6036207606b56.pdf
    • https://paxuwuberuluza.weebly.com/uploads/1/3/1/3/131380725/e38e321f84253a8.pdf
    • https://kolofajek.weebly.com/uploads/1/3/0/9/130969684/9889082.pdf
    • https://cdn-cms.f-static.net/uploads/4478131/normal_6056ab0dabb77.pdf
    • https://cdn-cms.f-static.net/uploads/4385213/normal_5fe76a9274350.pdf
    • https://jowetirepenu.weebly.com/uploads/1/3/1/3/131383619/c80c02d.pdf
    • http://copyrightnotice-ig.com/willy_wonka_and_the_chocolate_factory_torrentqkxi5.pdf
    • https://cdn-cms.f-static.net/uploads/4419626/normal_60174df5ceccd.pdf
    • http://koolmaxt.online/is_toshiba_regza_a_good_tvjdg8j.pdf
    • https://cdn-cms.f-static.net/uploads/4392652/normal_6050ee395ad27.pdf
    • http://about-igsupport.com/best_meditation_music_app_android99jqe.pdf
    • http://techanomic.com/multiply_polynomials_worksheet_doc1xj6x.pdf
    • http://lotsmen.com/sifevaxewozetaboxoxujovyfg8u.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://pefijolal.rf.gd/hasi_ban_gaye_lyrics_song.pdf
    • http://zamoguwudegovo.rf.gd/ib_biology_book_2020.pdf
    • https://b9eb3541-094c-4606-b101-17c2291fd6e1.filesusr.com/ugd/a18601_e5f242a58dfe4384b4886e74d4c70f2f.pdf?index=true
    • https://0f7a2101-273c-4f7f-b1fd-079d1ad923c1.filesusr.com/ugd/a7ea6f_be888e5f07164b1d9d2c52cc8ba70c46.pdf?index=true
    • http://terunakef.rf.gd/abstract_nouns_worksheets_grade_5.pdf
    • https://1482387f-61d8-47e1-b538-9b7f1e8b89fb.filesusr.com/ugd/538d67_0a3c840a57784853bb131136c2fba227.pdf?index=true
    • https://b23ebcb4-2e41-4c68-a408-584c84124782.filesusr.com/ugd/5a2446_b39e191c989046ed8605bb8d19b2ed70.pdf?index=true
    • http://tawurogaxe.epizy.com/basics_of_computer_engineering_book.pdf
    • http://kelovikaxovixu.epizy.com/maytag_maxima_front_load_washer_problems.pdf
    • https://4541bc1c-e35c-4de3-bb44-1f53c3e1a56d.filesusr.com/ugd/68f66e_31188c8b0cbf4a3f8020764a5d108e83.pdf?index=true
    • http://dibulorofo.epizy.com/cristianismo_y_liberalismo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000da78.bin
e9655c79db30b82c1cf11484845f64999358954864a5c8010c4207051f4712ee
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA78 5520 bytes
font_01_sfnt_off0000ed6b.bin
467474b1e3168127627ab99dec6b82434644cb66480d4f3d50e29f943a87a8d2
pdf-font-stream PDF embedded font (sfnt) at offset 0xED6B 2572 bytes
font_02_sfnt_off0000f8b3.bin
81a1035e444fffd25afced6a6e25b56edf30c2da4f470d56a4c08310333d944f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8B3 11164 bytes
font_03_sfnt_off00011f33.bin
4b39140c652e6d058fe59e0172338ed7e0b8c56e7cdf0ba82c6c8c4172db5d18
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F33 16144 bytes