Malicious PDF — malware analysis report

Static analysis result for SHA-256 a140704cdbaa5f62…

MALICIOUS

PDF

66.8 KB Created: 2021-01-03 13:46:45 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: a712982209f8e16f278e7709f88b866e SHA-1: 652c5fe892adc94ab93d7aee80a218dfa44de96e SHA-256: a140704cdbaa5f62f71ebfe83f36cc14cd37086baa9c6773edc232eedcaae139
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file exhibits characteristics of a phishing or malicious link farm, as indicated by the 'PDF_SEO_LINK_FARM' heuristic and the presence of numerous external URLs. The 'ML_NYX_PDF_MALICIOUS' and 'CLAMAV_DETECTION' heuristics strongly suggest malicious intent. While no scripts were explicitly extracted, the structure and heuristics point towards the document being used to distribute malicious content or redirect users to phishing sites, likely via embedded JavaScript or other exploit vectors.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/aws?utm_term=bullet+bike+status+video PDF link annotation
    • https://nivagevap.weebly.com/uploads/1/3/1/4/131438423/nunadafumekof.pdfIn PDF document text
    • https://cdn.sqhk.co/rubovadu/dhfrjgp/syfy_movies_halloween.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408172/normal_5fb4dc701a15c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4380857/normal_5fdab8e5204ec.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365608/normal_5fb6aef57d40a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374954/normal_5f993c2401df1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4371240/normal_5fa283bfda8c2.pdfIn PDF document text
    • https://korodaziso.weebly.com/uploads/1/3/0/7/130740443/7654624.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://s3.amazonaws.com/divikufifir/fallout_shelter_apk_cheat.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a5391094-116d-485a-acd8-2d8dc4aeb7e9/zomomofexafevusojiruretor.pdfIn PDF document text
    • https://s3.amazonaws.com/pusori/nctb_ebook_free.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d74e9c21-b488-4897-b193-8d3c8714a50c/nixasuvukufusujuvas.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bcab.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBCAB 5036 bytes
SHA-256: 9b82696196ee26d8d219cc37d5647c5dde1c8f1ab28c7ae8f788f6d7ac86a437
font_01_sfnt_off0000cde2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCDE2 9452 bytes
SHA-256: e2b3151f944f7a9908c437007fd3d6116315714ee633b8d330cc62ca9cf41b31
font_02_sfnt_off0000ee80.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEE80 4332 bytes
SHA-256: 5470b69f2f6683a27e6b51e1ac0a4d37c4ab233abc1e83e6e36ee98480062026