Malicious PDF — malware analysis report

Static analysis result for SHA-256 946a28590152e0e6…

MALICIOUS

PDF

69.0 KB Created: 2020-11-13 22:11:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5a1423ad0a729dcdfef0a541a4656c27 SHA-1: 1a1f3143366db65d014ce731bf8bf17a9cb28b1a SHA-256: 946a28590152e0e6f2e4897f5d4adb25a12a285213d23a301ab6838503042246
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to PDF files hosted on file-sharing services, indicative of a link farm. The ClamAV detection and ML classifier strongly suggest malicious intent, likely phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and embedded URLs point towards an attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/123?utm_term=matrix+data+analysis+techniques
    • https://milorupubi.weebly.com/uploads/1/3/4/3/134317418/357011aa3.pdf
    • https://naligunuded.weebly.com/uploads/1/3/4/4/134472871/xukalividuwan-vureduridubi-peluzibuzevo.pdf
    • https://cdn-cms.f-static.net/uploads/4367941/normal_5f892497f1064.pdf
    • https://xogexemufak.weebly.com/uploads/1/3/1/4/131437987/6112377.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/577b95ce-1f0a-4078-b7f7-f7f881998c8d/3595225786.pdf
    • https://uploads.strikinglycdn.com/files/096ddced-1c3a-49bb-9eb9-bf2cab6cb909/67190056232.pdf
    • https://uploads.strikinglycdn.com/files/2dfd2674-9b94-4a34-b5d4-38e0d5e437c4/frigidaire_oven_f10_warning.pdf
    • https://s3.amazonaws.com/zafirawit/gi_guidelines_diverticulitis.pdf
    • https://uploads.strikinglycdn.com/files/79203e43-8d29-4dab-a114-356c442fceed/49305639388.pdf
    • https://uploads.strikinglycdn.com/files/a961d010-5789-4943-996a-6705fda01dde/actron_cp9580a_software_update.pdf
    • https://s3.amazonaws.com/wunojipu/sedufewutefasipobuvine.pdf
    • https://uploads.strikinglycdn.com/files/15371d8e-b2f1-4a84-9c7e-71813efbd0e0/zujeviwadevukijapo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d2c4.bin
d732cff1c3030e647f293dbf713c7b33f424a6d8c8d42d2a5ce8e93b32edca3c
pdf-font-stream PDF embedded font (sfnt) at offset 0xD2C4 5328 bytes
font_01_sfnt_off0000e4ef.bin
d16d5079343de0f17f690ff50d4965c41a4ae6b3107e2fc09da90b7bce7dc1f1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE4EF 10108 bytes