Malicious PDF — malware analysis report

Static analysis result for SHA-256 a75a853840981347…

MALICIOUS

PDF

98.9 KB Created: 2021-03-19 07:48:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c6379cda06d3c9bb8546175386a861d1 SHA-1: 5b417ddff2e9f5dae8cc5d39b95db464c0cec698 SHA-256: a75a853840981347e43e0d892978459778cb4bade5b0c9148e5ac424ef9f1bb4
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many pointing to PDF files hosted on various domains and cloud storage services. This behavior is indicative of a link farm, often used for SEO manipulation or to distribute malicious content. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution through these linked documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9953

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/award?keyword=cellula+eucariote+animale+pdf
    • https://cdn.sqhk.co/totafeta/Vhhide0/stickman_reaper_apk_download.pdf
    • https://cdn.sqhk.co/gixenako/gfhhjaM/prize_claw_apkpure.pdf
    • https://lazumuron.weebly.com/uploads/1/3/4/8/134863931/xunidep-xubovagaxufubuk-sedozu-tupudizasado.pdf
    • https://xofajusas.weebly.com/uploads/1/3/1/0/131069744/funiferi-zuvopuxad-medutuxa-pivesogaremenad.pdf
    • https://vetazewufa.weebly.com/uploads/1/3/2/8/132814418/48e717d.pdf
    • https://cdn-cms.f-static.net/uploads/4377706/normal_602af44558252.pdf
    • https://static.s123-cdn-static.com/uploads/4393635/normal_60024988933be.pdf
    • https://reratedazakowim.weebly.com/uploads/1/3/1/3/131378897/boxogafagoladi.pdf
    • http://tagaporigowekis.mygamesonline.org/45719183582.pdf
    • https://cdn-cms.f-static.net/uploads/4367648/normal_5fe775b59de19.pdf
    • http://mavafesumej.medianewsonline.com/97466152262.pdf
    • https://popetebebulexu.weebly.com/uploads/1/3/4/3/134316921/zejajapefijomuxazi.pdf
    • https://vasuwogi.weebly.com/uploads/1/3/4/0/134017955/zekidepajeb_zinezadobi.pdf
    • https://cdn.sqhk.co/moviferu/h8FhfmC/adventure_academy_code_for_free.pdf
    • https://cdn.sqhk.co/xibetevoxaj/Njajhjc/40455921820.pdf
    • https://cdn.sqhk.co/tuxonewebuke/JpOhfzv/across_age_2_mod_apk.pdf
    • https://gesofomudejow.weebly.com/uploads/1/3/4/3/134344239/fab811.pdf
    • https://static.s123-cdn-static.com/uploads/4368958/normal_5fddd0a75a13f.pdf
    • https://cdn.sqhk.co/satukevaguka/gWccche/keberuvumijulire.pdf
    • https://cdn.sqhk.co/muwunupudi/Khesgic/gezamamujitupowefizisulut.pdf
    • https://zobovakobazazu.weebly.com/uploads/1/3/4/3/134319401/futanokikomori.pdf
    • http://xubajur.mygamesonline.org/black_swan_books_oakland.pdf
    • https://panesiwosejel.weebly.com/uploads/1/3/0/7/130739396/jodatit.pdf
    • https://cdn.sqhk.co/futevanu/hfC1ghI/bovitonaxoluleragagosep.pdf
    • http://kixiwogazu.sportsontheweb.net/ball_bearing_material.pdf
    • https://cdn.sqhk.co/lizuloka/erfhhhg/lagupurusifelezigivabomi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://vifidumefitur.atwebpages.com/transferencia_de_tecnologia_definicion.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00014047.bin
71803651f8d5c2f03abed4d13009b967fd082e1b04987770dd1d45398512f9a4
pdf-font-stream PDF embedded font (sfnt) at offset 0x14047 5028 bytes
font_01_sfnt_off0001514a.bin
6dae5dd13e017ffc48aa5e708b3f325ed1a9ddbe134a8bf0927e030437e0e2a2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1514A 13776 bytes