Malicious PDF — malware analysis report

Static analysis result for SHA-256 830f2fd76b0bcdce…

MALICIOUS

PDF

97.4 KB Created: 2020-12-21 20:46:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 116827f7b4426c901c0302b37ce35944 SHA-1: 57b95110e6cd49465ac75780284cbc41c3f33e66 SHA-256: 830f2fd76b0bcdce8684969fee728ce9b95b40056e51a1a4cf13b16d96ef1a66
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, identified as a link farm, with one prominent URL leading to a site that appears to be a search result. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and the presence of external links suggest an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9959

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=heartstrings+meaning+in+malayalam
    • https://cdn-cms.f-static.net/uploads/4501042/normal_5fb5f3aa49ee7.pdf
    • https://vokevifiv.weebly.com/uploads/1/3/4/6/134657891/xepewuxuzerujig.pdf
    • https://static.s123-cdn-static.com/uploads/4379970/normal_5fdf3b9c1e80d.pdf
    • https://wanezevidika.weebly.com/uploads/1/3/4/5/134588498/xapekujapiteno.pdf
    • https://xexiwimelogodit.weebly.com/uploads/1/3/4/5/134593193/gizosebotefiterit.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102Hussain
    • http://smc.org.inhttp://smc.org.in
    • https://uploads.strikinglycdn.com/files/60a3caa8-8acc-4bec-9087-ae7eeb540161/xoketigulotuvoga.pdf
    • https://uploads.strikinglycdn.com/files/e3fd1217-f34f-4334-abac-891bd67a9622/filelinamidawos.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5c5ef8cdb769c6da48bb/1606376543269/roland_barthes_camera_lucida_trke.pdf
    • https://uploads.strikinglycdn.com/files/d0a8ad63-8478-4774-bc43-7760f495084c/13710912864.pdf
    • https://static1.squarespace.com/static/5fc528f2abaecd33183df1a5/t/5fc6f127a907d7439ccd1632/1606873383822/leatherman_multi_tool_knife.pdf
    • https://static1.squarespace.com/static/5fc54e01085bf90c0e1a4b0c/t/5fca46ce414f5e3523868953/1607091938146/16580074360.pdf
    • https://static1.squarespace.com/static/5fc55163d49dd124475193a8/t/5fcdcfeb05ddc9599d431e7a/1607323628556/elfster_secret_santa_shareable_wishlist_app_store.pdf
    • https://uploads.strikinglycdn.com/files/73af4439-7c8d-41b8-ae2f-f8ec2d38c69a/32227293616.pdf
    • https://static1.squarespace.com/static/5fc0da75085bf90c0efcd65a/t/5fc357b3a97599144e629505/1606637492002/dragon_ball_z_games_unblocked_76.pdf
    • https://static1.squarespace.com/static/5fdd37006394b41d6424d862/t/5fde69475809ae3434fae880/1608411464634/65144759434.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL
    • https://gitlab.com/smc/meera/blob/master/COPYING

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_010_off00015970.bin
639f533dc3d59dab8f31e5d570f067b22abb569f411b42e7fafda2910e46530e
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x15970 17552 bytes
font_00_sfnt_off0000c733.bin
2599871317e27d8d02e9dd8b6a4cf193a6c2551b6111d1c1b58b2c2c6c64eb87
pdf-font-stream PDF embedded font (sfnt) at offset 0xC733 3544 bytes
font_01_sfnt_off0000d3e9.bin
29343c394cd2be63d5b2605e020233290c335fc988e5c18ceaab9fdbf599d23f
pdf-font-stream PDF embedded font (sfnt) at offset 0xD3E9 5068 bytes
font_02_sfnt_off0000e515.bin
dbaab8dcf32bfe64cb008f34eb54f5316f62236e8dffe3de49b44225404383a5
pdf-font-stream PDF embedded font (sfnt) at offset 0xE515 2656 bytes
font_03_sfnt_off0000f012.bin
12939d4d091da47a70d755e4e391669bade756e900abf4a3120506aea3309e7e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF012 12192 bytes
font_04_sfnt_off000117c3.bin
864cbe2c6973b44d2b71e19ffbffb2328dcb3759b07ceb43c11d5a372fc4956d
pdf-font-stream PDF embedded font (sfnt) at offset 0x117C3 2328 bytes
font_05_sfnt_off00012279.bin
d117309382da938f7dffedc42f90dd4217b4d540d75629b80669d975ecbc171e
pdf-font-stream PDF embedded font (sfnt) at offset 0x12279 2108 bytes
font_06_sfnt_off00012c4f.bin
2ea751e5d542f02fa4141a0932d8da91f5d5cdd41bd6d4746499e5e47228c1da
pdf-font-stream PDF embedded font (sfnt) at offset 0x12C4F 15060 bytes