Malicious PDF — malware analysis report

Static analysis result for SHA-256 c28b95560aa5eac2…

MALICIOUS

PDF

66.9 KB Created: 2020-12-05 11:39:59 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 647f34898c5f06ce801c03a9ce9b074b SHA-1: 76332211ccfc21a82f4a66c80aaedbbdca3acd85 SHA-256: c28b95560aa5eac24097eb2b15f1eb5d7650d5c6e081c666ff2f86724d0c5e13
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many pointing to Weebly-hosted PDFs, suggesting a link farm or SEO spam operation. The ClamAV detection and ML classifier indicate malicious intent, likely phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and heuristic firings strongly suggest it's designed to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/123?utm_term=best+french+action+movies+of+all+time
    • https://jamexujibelesuw.weebly.com/uploads/1/3/4/7/134748805/307c70ed5f56.pdf
    • https://ruparowix.weebly.com/uploads/1/3/4/3/134350000/f6baf99a8eeba.pdf
    • https://lataladegizozav.weebly.com/uploads/1/3/4/6/134685495/2680c3.pdf
    • https://pefuxagofir.weebly.com/uploads/1/3/4/3/134359429/5f8ae81e80f8d5.pdf
    • https://pumutetigowon.weebly.com/uploads/1/3/4/6/134699291/botan.pdf
    • https://wemibevufiwoseb.weebly.com/uploads/1/3/0/8/130813314/7de389f3c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/fb0682b3-9a43-4508-9efe-6ba867125d5b/25127015868.pdf
    • https://uploads.strikinglycdn.com/files/55db4593-62fe-4fd6-879c-6cef08d548e1/38885265547.pdf
    • https://uploads.strikinglycdn.com/files/9ce14265-8080-4358-b249-65e10873d91c/dermalmd_under_eye_serum.pdf
    • https://uploads.strikinglycdn.com/files/0a421b5a-6c82-4e1a-97e8-75b193786839/44218254147.pdf
    • https://uploads.strikinglycdn.com/files/aec44298-bcc6-40b6-95a4-eb43fe9f69fe/89171552909.pdf
    • https://uploads.strikinglycdn.com/files/ab88b380-ec81-42ed-963f-d50ae0176c91/44727677588.pdf
    • https://uploads.strikinglycdn.com/files/df21dea1-d60a-41ca-9ea7-7b87953726be/61099593277.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c6ae.bin
97c89ff72a747cc29509040d8a8034e5822b8978a5faf615deaeffda45fd3f52
pdf-font-stream PDF embedded font (sfnt) at offset 0xC6AE 5228 bytes
font_01_sfnt_off0000d859.bin
ce687cfd784a8b9eac9e741ae60b282729bfbcf1a7066faf3dc66a9f7dc5ab62
pdf-font-stream PDF embedded font (sfnt) at offset 0xD859 11140 bytes