Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3c7ad1fbdd61ca7…

MALICIOUS

PDF

78.6 KB Created: 2021-03-24 04:17:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 965b30bcb5b891786c1480839dece426 SHA-1: b275aa7e1f92251cb1a79ae002f6755bce50c06b SHA-256: a3c7ad1fbdd61ca70c469d3b2187877ade0369a32ffacf7f44e32f42171ea2d2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are structured as SEO link farms, indicating a malicious intent to redirect users to potentially harmful sites. The document body, though heavily obfuscated, suggests a lure related to 'crossword answers'. The presence of ClamAV and ML heuristic firings further supports its malicious classification. No scripts were extracted, but the PDF structure itself facilitates the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=us+constitutional+amendments+crossword+answers
    • https://static.s123-cdn-static.com/uploads/4416131/normal_5ff4ec07110a4.pdf
    • http://jakusavu.sportsontheweb.net/16366922121.pdf
    • http://fivadoguna.medianewsonline.com/what_is_the_terminally_ill_patient_autonomy.pdf
    • https://vavodegan.weebly.com/uploads/1/3/5/3/135398560/kajugezobasi.pdf
    • https://bogekivusuwi.weebly.com/uploads/1/3/4/6/134604255/zavifejefede.pdf
    • https://fupuvoriru.weebly.com/uploads/1/3/4/4/134494751/takiw.pdf
    • http://jamarifuto.iblogger.org/how_to_cook_1_year_old_baby_food.pdf
    • https://kokesekodabese.weebly.com/uploads/1/3/4/0/134012443/zuluwomidedafu-lojomi.pdf
    • https://cdn-cms.f-static.net/uploads/4369164/normal_601110baeae3e.pdf
    • https://cdn-cms.f-static.net/uploads/4468294/normal_60230fa8a70dc.pdf
    • http://xufededubumavif.scienceontheweb.net/como_se_hace_un_manual_de_usuario.pdf
    • http://wovugikanagak.scienceontheweb.net/ancient_greek_civilization_sansone.pdf
    • https://majivuwuwu.weebly.com/uploads/1/3/2/6/132683475/40d5ca.pdf
    • https://cdn-cms.f-static.net/uploads/4492892/normal_600ce3b68f27b.pdf
    • https://cdn-cms.f-static.net/uploads/4372371/normal_603d0a06e953c.pdf
    • https://gedibixofesona.weebly.com/uploads/1/3/4/6/134688069/6469037.pdf
    • https://xetupowo.weebly.com/uploads/1/3/1/3/131382232/42ab318e5a548be.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://webidiwotew.epizy.com/8111934857.pdf
    • http://kowelakava.rf.gd/tatowivegibafonutexosived.pdf
    • http://bekonoxidolu.rf.gd/10495504679.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5ad.bin
2858bae9fd85008911d83cf05aaeabfe9ac47950cd53d23e77b6756797c11f1c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5AD 5168 bytes
font_01_sfnt_off00010739.bin
cf50442643e753dafbb5ef574642728afe3262268d0c476952303329328c89bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x10739 11120 bytes