Malicious PDF — malware analysis report

Static analysis result for SHA-256 a1bba402926226df…

MALICIOUS

PDF

73.9 KB Created: 2021-05-31 20:41:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6436c1964baee28ef5b57cd38df0a9d3 SHA-1: b490527425278a13fb4686abd415033d967296a1 SHA-256: a1bba402926226df6da1e52dc149f3eb3e04fe763a6456cc6de317ecb943fad8
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. It contains a large number of external links, suggesting a link farm or phishing attempt. The document's structure and the presence of embedded URLs indicate it is designed to redirect users to malicious sites, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cructi.ru/pbw?utm_term=invention+and+innovation+worksheet
    • https://cdn-cms.f-static.net/uploads/4421767/normal_603ba2ca07766.pdf
    • https://cdn-cms.f-static.net/uploads/4503033/normal_60272f26e7773.pdf
    • https://tosabavol.weebly.com/uploads/1/3/0/8/130813831/32904c6567f15.pdf
    • https://lojumokixawivi.weebly.com/uploads/1/3/4/3/134370302/tarevu_lezigakorup.pdf
    • https://fokopudetetubuw.weebly.com/uploads/1/3/4/5/134519343/3625603.pdf
    • https://cdn-cms.f-static.net/uploads/4385880/normal_606dd29090acc.pdf
    • https://wiwanozamo.weebly.com/uploads/1/3/4/3/134306351/vogeker.pdf
    • https://static.s123-cdn-static.com/uploads/4412582/normal_60081d93b81a9.pdf
    • https://gebigimudixerez.weebly.com/uploads/1/3/4/3/134374499/2c05ef174d1a.pdf
    • https://nunavupogo.weebly.com/uploads/1/3/4/4/134471291/5185564.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/175e72e9-a693-4355-84ca-20637861e3c4/delta_crib_set_target.pdf
    • https://uploads.strikinglycdn.com/files/062a1940-524e-4c33-a313-0d0c1fe71149/dafodavajilalib.pdf
    • https://uploads.strikinglycdn.com/files/e63414f6-ea7d-402a-90ce-a00fbed7c693/vosokarebijiza.pdf
    • https://uploads.strikinglycdn.com/files/c70354ed-8080-49eb-8722-b42233f23101/utilitech_sump_pump_replacement_parts.pdf
    • https://uploads.strikinglycdn.com/files/e94202ad-839d-4aa3-afa9-f7005793ebf3/79280037740.pdf
    • http://poxanoralanu.pbworks.com/f/punchline_algebra_book_b_answer_key_quadratic_equations_and_functions.pdf
    • http://masawumel.pbworks.com/w/file/fetch/144420687/math_logic_problems_and_answers.pdf
    • https://uploads.strikinglycdn.com/files/b2fbdd9b-3406-486f-8ec6-e011d8134aa0/cuantas_semanas_tiene_el_ao_escolar.pdf
    • https://uploads.strikinglycdn.com/files/820b7f6d-2eb6-4bc5-9191-8dcb3a09f15c/betty_crocker_cookbook_recipe_for_peanut_butter_cookies.pdf
    • http://tisowowuduwe.pbworks.com/f/28667186608.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e364.bin
7abd09271cdf8dc7a74168717f2d4e481145f4eb889c59734d50b77c79de8524
pdf-font-stream PDF embedded font (sfnt) at offset 0xE364 5036 bytes
font_01_sfnt_off0000f498.bin
6f2ba58dd0a9bf571ffe92eac5995fec852a4bc746471d9ab5b4739be0f1e8e7
pdf-font-stream PDF embedded font (sfnt) at offset 0xF498 11256 bytes