Malicious PDF — malware analysis report

Static analysis result for SHA-256 9efd9594d494d0c9…

MALICIOUS

PDF

78.7 KB Created: 2021-03-11 09:34:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 69fd4932e48ed74a00dae95e96154b0e SHA-1: 7ddcb65b1c2f081abe826a2e539655e552d10709 SHA-256: 9efd9594d494d0c9725d2944ce5da62f0458c977486e073a5881d0d69c2781e3
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The file contains a large number of external links, suggesting it is part of a link farm designed to drive traffic to potentially malicious or phishing websites. The primary lure appears to be related to "Cuento de axolotl pdf", directing users to external URLs for further engagement.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=cuento+de+axolotl+pdf
    • https://wisamifogafize.weebly.com/uploads/1/3/4/5/134598642/bc2e205.pdf
    • http://nitanupemil.mygamesonline.org/6898357629.pdf
    • http://pakirekugep.scienceontheweb.net/41384206265.pdf
    • http://mapotilij.mygamesonline.org/22952052468.pdf
    • https://cdn.sqhk.co/xudekutof/oijpjhp/buwuwubiridiriborunive.pdf
    • https://renikafajuwigag.weebly.com/uploads/1/3/4/3/134317319/basiwudabejisobotuv.pdf
    • https://cdn.sqhk.co/sitopizol/hahdjhz/king_koin_laundry_truro_ns.pdf
    • https://cdn.sqhk.co/rozopebak/ojagfig/81097525954.pdf
    • http://jadogaxarabu.mygamesonline.org/about_face_the_essentials_of_interaction_design_4th_edition.pdf
    • https://cdn.sqhk.co/vegedusovo/hinvTBL/70721511616.pdf
    • https://cdn.sqhk.co/pegipoveridi/jhagUhi/this_war_of_mine_mod_apk_revdl.pdf
    • https://cdn.sqhk.co/xonarewu/2RiauyX/hdv_1080i_sony_manual.pdf
    • https://cdn.sqhk.co/tibakekavero/igDDVjf/preset_free_presets_for_lightroom_mobile_mod_apk.pdf
    • http://nokasosozigof.mypressonline.com/80823988966.pdf
    • http://suwadebizon.mywebcommunity.org/tecnologia_educativa_unesco.pdf
    • http://zipubezexupoka.mywebcommunity.org/mosawimorewezimekeselulo.pdf
    • https://cdn.sqhk.co/depifozopupe/Ajdjijg/32908335824.pdf
    • http://tunewejewuz.mypressonline.com/half_life_questions_and_answers_igcse.pdf
    • http://fobativ.mywebcommunity.org/what_is_default_ip_address_camera_in_hikvision.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fukuselumetu.myartsonline.com/amway_all_products_price_list_2020.pdf
    • http://gifidabula.atwebpages.com/lewetebupazejadedisiv.pdf
    • http://wutejaxevewef.myartsonline.com/alto_and_tenor_sax_duets.pdf
    • http://zisukuvi.atwebpages.com/kidde_smoke_and_carbon_monoxide_alarm_battery_operated.pdf
    • http://nejesezape.myartsonline.com/marketing_manager_jobs_dubai_salary.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5e2.bin
56dc0a785e4497863d87999681a58ae3ed1b1bedddb218a7d40a8a30a721f89a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5E2 4732 bytes
font_01_sfnt_off00010616.bin
0f4da62e9e3efa066f31ca7ee0c2fd2f81ccdd5195db3a768828352f1c7ceffe
pdf-font-stream PDF embedded font (sfnt) at offset 0x10616 11492 bytes