Malicious PDF — malware analysis report

Static analysis result for SHA-256 c1f6833224c60f24…

MALICIOUS

PDF

72.4 KB Created: 2021-05-31 23:12:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ce306c1861691e404c4ab33f278fa7d5 SHA-1: 763a981d8b1d54e8f805af6e1f5423a00ef03e21 SHA-256: c1f6833224c60f24b4f44e00e8f3b6f770732e5555b5ea94f57f4489209b30e3
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which point to other PDF documents, indicating a link farm designed to manipulate search engine results or direct users to potentially malicious content. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution through these linked resources. No scripts were extracted, but the structure and numerous external links are indicative of a phishing or traffic-generation scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cructi.ru/pbw?utm_term=how+to+repair+a+broken+brass+drawer+pull
    • https://pizewenijanud.weebly.com/uploads/1/3/0/7/130775868/1074865.pdf
    • https://gixunilaw.weebly.com/uploads/1/3/1/8/131856646/d727cb09.pdf
    • https://cdn-cms.f-static.net/uploads/4420454/normal_6054f9db7c327.pdf
    • https://cdn-cms.f-static.net/uploads/4466659/normal_5fdc3646c74aa.pdf
    • https://cdn-cms.f-static.net/uploads/4375340/normal_605b5a29da924.pdf
    • https://static.s123-cdn-static.com/uploads/4471995/normal_60025fe8403ae.pdf
    • https://static.s123-cdn-static.com/uploads/4489979/normal_5ff895dce9106.pdf
    • https://cdn-cms.f-static.net/uploads/4499329/normal_6047dd7bcd8be.pdf
    • https://cdn-cms.f-static.net/uploads/4420431/normal_5fd22729134a6.pdf
    • https://cdn-cms.f-static.net/uploads/4369507/normal_606008e2a4866.pdf
    • https://cdn-cms.f-static.net/uploads/4389606/normal_6047d1ad9f5f6.pdf
    • https://cdn-cms.f-static.net/uploads/4411700/normal_60464d808e9ef.pdf
    • https://cdn-cms.f-static.net/uploads/4488102/normal_602587d93b68a.pdf
    • https://wewiloviwa.weebly.com/uploads/1/3/4/5/134585183/7f09e82741ea26.pdf
    • https://cdn-cms.f-static.net/uploads/4480904/normal_6054b01e45256.pdf
    • https://wufezaju.weebly.com/uploads/1/3/0/7/130738917/maxafomusipijo.pdf
    • https://static.s123-cdn-static.com/uploads/4371267/normal_600839e250355.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/4e1a72d8-a985-40b7-9abe-c9938d744c7c/char_broil_pellet_grill_parts.pdf
    • https://uploads.strikinglycdn.com/files/947a6801-adaa-45fb-ab60-260455d8ffe9/how_to_explain_machine_learning_to_your_manager.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ddd2.bin
054cddaef3f2efa8ef68d18617f852de27fae9324ba78cde7be6ccf10901e810
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDD2 5208 bytes
font_01_sfnt_off0000ef99.bin
aa365ed6f7754ec03ba93d1413554da3ec570be135743c667bab29e14fdbca88
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF99 10676 bytes