Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3fa4859a62b7d90…

MALICIOUS

PDF

80.9 KB Created: 2021-05-31 02:24:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9a85a6aee3a8662dd8a4dcedaf8173e3 SHA-1: 23803296f14f555cf29bdcbb1b09e7ffeb1de93f SHA-256: b3fa4859a62b7d904f221c2b0221f7186a1e2ba2101575fa9d5b00a29120fb5c
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of external links, identified as a link farm, suggesting a malicious intent to redirect users. The ClamAV detection and ML classifier strongly indicate maliciousness, with the primary technique being Spearphishing Attachment. While no scripts were explicitly extracted, the PDF structure and embedded URLs point towards a phishing or SEO manipulation scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=can+you+be+both+vampire+and+werewolf+in+skyrim
    • https://wigawiwamenusum.weebly.com/uploads/1/3/5/3/135323889/9646663.pdf
    • https://cdn-cms.f-static.net/uploads/4472486/normal_605f5be653378.pdf
    • https://kikokowenut.weebly.com/uploads/1/3/4/7/134713101/633cd93e7945d.pdf
    • https://sunupukub.weebly.com/uploads/1/3/5/3/135319403/bcc3588246.pdf
    • https://finuvowevemez.weebly.com/uploads/1/3/5/3/135397693/kunujidoxasavawog.pdf
    • https://rilodogalaru.weebly.com/uploads/1/3/4/3/134398508/bazitukevepe.pdf
    • https://litusavetedi.weebly.com/uploads/1/3/4/4/134445261/nejemu_dewiwekoteg_buwubefojojupuv.pdf
    • https://gisidamuxifa.weebly.com/uploads/1/3/0/7/130775495/9988652.pdf
    • https://cdn-cms.f-static.net/uploads/4369794/normal_600e03ad9c302.pdf
    • https://gikotibosad.weebly.com/uploads/1/3/4/3/134332820/8c2cbd.pdf
    • https://static.s123-cdn-static.com/uploads/4380214/normal_5fefe69fe16e6.pdf
    • https://pezibife.weebly.com/uploads/1/3/4/3/134376528/dotokazobiro.pdf
    • https://feposejixadolo.weebly.com/uploads/1/3/4/7/134744373/pudarulifudi-tiresujo-saxebomaki-logajirovif.pdf
    • https://cdn-cms.f-static.net/uploads/4418192/normal_601731c83aade.pdf
    • https://wesoxiworikezux.weebly.com/uploads/1/3/1/3/131380467/virubizujenogom-wapim.pdf
    • https://jatisarekitikez.weebly.com/uploads/1/3/4/6/134661612/gasopixu-puxitedamarapun.pdf
    • https://static.s123-cdn-static.com/uploads/4391605/normal_5ffd71846f954.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/f4934e36-c958-49c9-b00d-84d2b9f922c4/gps_gf-07_imei_number.pdf
    • https://uploads.strikinglycdn.com/files/bbce4a6d-fd9f-4c68-885e-9b9f07dd825c/vivekepavalerokire.pdf
    • https://uploads.strikinglycdn.com/files/e120c885-1ab0-478f-b2e0-ca34d62f2aa6/75577311196.pdf
    • https://uploads.strikinglycdn.com/files/8ac3f4e0-95dd-483e-ae87-c1f4acf5415e/nevuni.pdf
    • https://uploads.strikinglycdn.com/files/937fd5fe-684b-4234-ae4f-3589c4b681cf/58640946808.pdf
    • https://uploads.strikinglycdn.com/files/06137a25-dd8f-45d7-bf57-adae37f1b76d/56658797209.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f093.bin
f35db4aadccc30c188a89a4a3fdb7d1f0e2de3ca2c01cca15b7b5e1e8dfa3dbe
pdf-font-stream PDF embedded font (sfnt) at offset 0xF093 5644 bytes
font_01_sfnt_off000103ae.bin
0ad88a93813274e1561008d0931a5234c535860bd2805362f5125cd2d1c03d6b
pdf-font-stream PDF embedded font (sfnt) at offset 0x103AE 10676 bytes
font_02_sfnt_off000127d1.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x127D1 4324 bytes