Malicious PDF — malware analysis report

Static analysis result for SHA-256 9304f7b1a1518b9f…

MALICIOUS

PDF

81.5 KB Created: 2021-03-25 05:27:09 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 190536e6dfe2dd961b79de74b6f8d8af SHA-1: 242e00219459f68163ef2924b22e1fb30382f645 SHA-256: 9304f7b1a1518b9f9d962ab5726f478ddc5f1d7ea6c4c36693a8c1d8a5c30e34
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of external links, many pointing to Weebly-hosted PDFs, indicative of a link farm or phishing campaign. The ClamAV detection and ML classifier strongly suggest malicious intent. The embedded URLs are likely used to redirect users to malicious sites for further exploitation or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/wix?keyword=a+raisin+in+the+sun+study+guide+act+1
    • https://wekupadafar.weebly.com/uploads/1/3/5/3/135315244/138573350c68.pdf
    • https://muxetomanudone.weebly.com/uploads/1/3/1/4/131406273/1292481.pdf
    • https://muvekova.weebly.com/uploads/1/3/5/3/135394778/guwazete-zelasabivumis-xibosuxoni.pdf
    • https://cdn.sqhk.co/toralapiluw/bjchaih/looperman_soul_samples.pdf
    • https://jenitexul.weebly.com/uploads/1/3/4/8/134859983/nijas_matoxakinazi_zazaziziweju.pdf
    • https://monubigikupo.weebly.com/uploads/1/3/4/4/134493781/88ea47a3f4e.pdf
    • https://pevunefimexog.weebly.com/uploads/1/3/1/0/131070247/ziruw-lowakuwexegaxi-netewasajerefem-gemaduboxika.pdf
    • https://sekagerufelijet.weebly.com/uploads/1/3/5/9/135965199/72e91980cc14cb.pdf
    • https://cdn.sqhk.co/wesuwajil/Bhd43jc/diary_of_a_wimpy_kid_wrecking_ball_bookmark.pdf
    • https://wobapuzufisuro.weebly.com/uploads/1/3/4/0/134042344/418703.pdf
    • https://zizobisorodevu.weebly.com/uploads/1/3/5/9/135964877/kodafarogazoponuj.pdf
    • https://kolijegidixut.weebly.com/uploads/1/3/1/3/131379325/c7055bfe34.pdf
    • https://zobanegasub.weebly.com/uploads/1/3/1/1/131164549/1e4fb72.pdf
    • https://cdn.sqhk.co/nepofigiper/iidij5R/oscar_de_la_hoya_family_tree.pdf
    • https://cdn.sqhk.co/mizopopowaze/igt5Dje/ultimate_spider_man_venom_gameplay.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/5048979b-d059-45af-bc67-3a41a4ed8387/jowugimadiva.pdf
    • https://s3.amazonaws.com/nazekisigiduz/c_programming_interview_questions.pdf
    • https://uploads.strikinglycdn.com/files/19402450-8330-40dd-9bec-902a70f15c44/61071547808.pdf
    • https://uploads.strikinglycdn.com/files/33060e1c-10c3-42bd-a837-1a1aba780d93/badowurobaduvujiguxo.pdf
    • https://uploads.strikinglycdn.com/files/d77a44ba-45bd-471b-a285-5be0cf3ac114/how_to_connect_to_wifi_samsung_printer.pdf
    • https://s3.amazonaws.com/gupojakami/37117353284.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f488.bin
b05f5e1e15b34d2bc664be2e79089496cdde2aee220a22f69fa2f596a56a8ed1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF488 5084 bytes
font_01_sfnt_off000105cb.bin
652158fb57ca8dab3c3e640365e094d49262d1077e61a9c2410d6e899c81fbe5
pdf-font-stream PDF embedded font (sfnt) at offset 0x105CB 10812 bytes
font_02_sfnt_off00012a95.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x12A95 4324 bytes