Malicious PDF — malware analysis report

Static analysis result for SHA-256 8806a031e8702182…

MALICIOUS

PDF

79.7 KB Created: 2021-05-22 02:20:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d80e3a318cb491d5b64c3c104d7d1b25 SHA-1: a0a579a12b0a044c6f5269816eabfa6733a92010 SHA-256: 8806a031e8702182aadd892eaa9db5e095f123d63d9acd5f132510723c1cfbbe
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a heuristic firing for a 'PDF_SEO_LINK_FARM' which indicates a large number of external links, with one prominent URL pointing to 'golowaki.ru'. ClamAV also detected this as 'Pdf.Phishing.Trojan'. The presence of embedded URLs and the ML classifier's high confidence score suggest a malicious intent to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/strik?utm_term=dragon+age+inquisition+rogue+build+reddit
    • https://cdn-cms.f-static.net/uploads/4494429/normal_6023d9dadafc1.pdf
    • https://static.s123-cdn-static.com/uploads/4379369/normal_5fecec201cfaa.pdf
    • https://woxoxoba.weebly.com/uploads/1/3/4/8/134893248/2659300.pdf
    • https://sinonulu.weebly.com/uploads/1/3/4/6/134654736/47e852f77.pdf
    • https://jogotipopawufi.weebly.com/uploads/1/3/0/7/130740597/wefokube.pdf
    • https://cdn-cms.f-static.net/uploads/4471960/normal_5fe6cef9e86d5.pdf
    • https://cdn-cms.f-static.net/uploads/4388842/normal_605c3b0920485.pdf
    • https://cdn-cms.f-static.net/uploads/4369507/normal_6023fd5edd869.pdf
    • https://subisadorug.weebly.com/uploads/1/3/1/6/131637552/9488677.pdf
    • https://vurejubi.weebly.com/uploads/1/3/1/4/131454114/forumeziruwi.pdf
    • https://gumelajijepepa.weebly.com/uploads/1/3/4/6/134639918/tegen-lobiv-kafufonediw.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/naxozelozude/48586657910.pdf
    • https://uploads.strikinglycdn.com/files/165e9129-97c2-40f7-bf63-8a8d0248630d/how_to_sanitize_spectra_s1_parts.pdf
    • https://uploads.strikinglycdn.com/files/c1469058-66a4-47c4-831a-d07f61b61106/jadufunefadudagididus.pdf
    • https://uploads.strikinglycdn.com/files/b76f992b-2b86-462d-923a-6f649f91d725/4660008912.pdf
    • https://uploads.strikinglycdn.com/files/16c3b269-d6aa-4a1f-9000-7c2d4e9d56c3/nejukuzemigu.pdf
    • https://s3.amazonaws.com/marimejerebo/what_is_the_best_k_cup_coffee_maker.pdf
    • https://uploads.strikinglycdn.com/files/1da22a94-cd74-49b8-9b6c-2745ac5f95d7/27200394145.pdf
    • https://uploads.strikinglycdn.com/files/21a03ce0-f00c-4bf8-a709-22e05ca5347c/coleman_rv_air_conditioner_15_000_btu_-_white_-_48204c866.pdf
    • https://s3.amazonaws.com/nademopor/58277149038.pdf
    • https://s3.amazonaws.com/bexolamabad/building_technology_reviewer.pdf
    • https://uploads.strikinglycdn.com/files/c947a898-8e91-4b0f-a380-5eeb47231523/lakshmi_narasimha_karavalamba_stotram_lyrics_tamil.pdf
    • https://uploads.strikinglycdn.com/files/c6f9f689-7bec-446e-8caa-897922da6b41/python_cookbook_3rd_edition.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f7e7.bin
153318e2ca11bbe641560078370e00fd38f6fc4af906189dda713083df7ac55b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF7E7 5260 bytes
font_01_sfnt_off000109c8.bin
2b71ae64b187a9c0e3510192bbcb927d15d30114ef0c28b88203db5686d0a232
pdf-font-stream PDF embedded font (sfnt) at offset 0x109C8 11172 bytes