Malicious PDF — malware analysis report

Static analysis result for SHA-256 b46450cf35e6513d…

MALICIOUS

PDF

93.6 KB Created: 2021-05-24 05:53:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-27
MD5: a6e880ec4cf4b15fe7e8bc607773b86a SHA-1: 1ed4a5e1de3a7d5d2a8c4efee37a6eb22804595d SHA-256: b46450cf35e6513d99d43b8cb41ba5e08436eb3cda33be0a3d11d3a27a51ab01
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a common tactic for phishing or malware distribution, as indicated by the PDF_SEO_LINK_FARM heuristic. The embedded URL and the ClamAV detection strongly suggest malicious intent, likely to trick users into downloading malware or visiting phishing sites. While no scripts were explicitly extracted, the PDF structure and URL patterns are indicative of a malicious document, possibly using embedded JavaScript for obfuscation or redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=download+far+cry+4+arena+master+mod+apk PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4383128/normal_606462b380fb0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4371261/normal_5fcb0f66a722b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4465543/normal_6012dc2d6ea2b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4474752/normal_601835be7cf11.pdfIn PDF document text
    • https://fubexomufepa.weebly.com/uploads/1/3/4/8/134850999/kelomeluzimomisog.pdfIn PDF document text
    • https://rijumiwotoresu.weebly.com/uploads/1/3/4/4/134490354/wujezogo-wizabumuwi.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/tiniruru/bafx_obd2_not_connecting.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dd2287d3-06ae-44ce-a387-af7dada4a674/how_to_manage_visual_hallucinations.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ffd2ffd1-0d03-4054-a7f5-8208a6bb74d1/nikira.pdfIn PDF document text
    • https://s3.amazonaws.com/zumezeviwakiz/jedure.pdfIn PDF document text
    • https://s3.amazonaws.com/vabedafozo/dubiwupovosepogorujewula.pdfIn PDF document text
    • https://s3.amazonaws.com/niwotipugonuvoz/56012925553.pdfIn PDF document text
    • https://s3.amazonaws.com/bipovoromoj/effective_communication_skills_in_mental_health.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/23aef222-3644-44c6-b1c6-940a3f598373/pafomaritixetivelefog.pdfIn PDF document text
    • https://s3.amazonaws.com/pozokimepe/83564432440.pdfIn PDF document text
    • https://s3.amazonaws.com/petuzutemixuvod/32837194841.pdfIn PDF document text
    • https://s3.amazonaws.com/dadupawo/asus_crosshair_iv_formula_usb_3.0_driver.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2034cdd4-56fb-4795-a782-5f75a348d400/27738060920.pdfIn PDF document text
    • https://s3.amazonaws.com/najubu/google_chrome_portable_32_bits.pdfIn PDF document text
    • https://s3.amazonaws.com/wudibirewuduto/square_appointments_app_android.pdfIn PDF document text
    • https://s3.amazonaws.com/xalexojaxipud/kundli_making_software_in_gujarati_free.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001223a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1223A 2960 bytes
SHA-256: 4c688c0676da4c9c3f1d636d29496b85ed1f90b4285ee9b780884cc7de0e34ac
font_01_sfnt_off00012caa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12CAA 5644 bytes
SHA-256: 3b6915d40df82f62282a93f74654ade13bdef8aff9aeeb6129e248fdbdd3efa7
font_02_sfnt_off00013ffa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13FFA 11928 bytes
SHA-256: 4621348d64e03fc5b605c8f4b0248c39d2bd46fb0b57a4d164ec0373f4e9350b