Malicious PDF — malware analysis report

Static analysis result for SHA-256 a6560ba4f1414235…

MALICIOUS

PDF

76.2 KB Created: 2021-02-08 23:51:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 850e10331ddadcd1971a648a6a60330f SHA-1: d0b9c516e891c6a87e6fe3fd8f3c29226cc3cb3d SHA-256: a6560ba4f14142357c6bfe17eae9ef80d40e57681994d641e2beaa920dad7f9d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by multiple heuristics and a machine learning classifier as malicious, specifically identified as a phishing trojan by ClamAV. The primary attack pattern involves a link farm, directing users to numerous external PDF documents, likely to manipulate search engine results or host further malicious content. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of its specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/wb?keyword=hummingbird%20resources%20annual%20report%202017
    • https://static.s123-cdn-static.com/uploads/4470220/normal_5fce231338386.pdf
    • https://vofovolovun.weebly.com/uploads/1/3/1/4/131483423/pekesav.pdf
    • https://cdn-cms.f-static.net/uploads/4408584/normal_601f96c5a5718.pdf
    • https://viwekaxirudadax.weebly.com/uploads/1/3/4/7/134700275/pekuvod.pdf
    • https://cdn-cms.f-static.net/uploads/4381973/normal_600cf58aa7c58.pdf
    • https://cdn-cms.f-static.net/uploads/4386095/normal_6017c35447ad7.pdf
    • https://cdn-cms.f-static.net/uploads/4465392/normal_601e331510a1f.pdf
    • https://static.s123-cdn-static.com/uploads/4471686/normal_5fe5e4c12c4a5.pdf
    • https://static.s123-cdn-static.com/uploads/4453553/normal_5fcf7c8dcac58.pdf
    • https://sinezotuze.weebly.com/uploads/1/3/0/9/130969777/df27706e.pdf
    • https://static.s123-cdn-static.com/uploads/4494891/normal_5ff026bd6c42b.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/jopomodilamego/84517787111.pdf
    • http://davagutuvis.rf.gd/31290065305.pdf
    • https://s3.amazonaws.com/pazerogasarinu/25338718298.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e996.bin
7d29406b838f3830b7a3804ae9583582b41053cf617a78f2cd8d697454f3f487
pdf-font-stream PDF embedded font (sfnt) at offset 0xE996 5900 bytes
font_01_sfnt_off0000fd9a.bin
4e987887123099a0bd0189a46394e82ad9af10763e745ad955bc0e62ac524d73
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD9A 11248 bytes