Malicious PDF — malware analysis report

Static analysis result for SHA-256 c3ea7d3a8569a3cc…

MALICIOUS

PDF

70.1 KB Created: 2020-11-11 16:54:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 25f1c293fa4845529b3abf8bac7954d1 SHA-1: 544230caae42ec0c479f09e37aa8aef7c1f0be4b SHA-256: c3ea7d3a8569a3cc2c7e4c129b66c7094ea5b359a51aaaaa0d261a7eeba95d78
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to PDF files hosted on services like Weebly and f-static.net, indicating a link farm designed to drive traffic to potentially malicious sites. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and numerous external links are indicative of a malicious campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/123?utm_term=9.3+two+special+right+triangles
    • https://dubuzosokiboxof.weebly.com/uploads/1/3/1/1/131163723/jakusedu.pdf
    • https://mekuxiwefajup.weebly.com/uploads/1/3/0/7/130739023/vajale_kutowuzawinajub_masewone_netulutud.pdf
    • https://cdn-cms.f-static.net/uploads/4402951/normal_5f91e3b25df25.pdf
    • https://cdn-cms.f-static.net/uploads/4365539/normal_5f929532c587b.pdf
    • https://cdn-cms.f-static.net/uploads/4386609/normal_5fa4cddb5d91a.pdf
    • https://cdn-cms.f-static.net/uploads/4374379/normal_5f8cad72db965.pdf
    • https://cdn-cms.f-static.net/uploads/4375894/normal_5f995aa0607fa.pdf
    • https://cdn-cms.f-static.net/uploads/4421623/normal_5fa583baabd02.pdf
    • https://nurixuwabojud.weebly.com/uploads/1/3/4/5/134587723/0aba6e9fb2c5.pdf
    • https://kivepuwepadile.weebly.com/uploads/1/3/4/3/134392404/fomegel.pdf
    • https://cdn-cms.f-static.net/uploads/4446273/normal_5fab1a23c0ecf.pdf
    • https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/rarikuravowupe.pdf
    • https://cdn-cms.f-static.net/uploads/4381291/normal_5f96b84001edc.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/kokesatodixon/2230827508.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bde2.bin
e66db40ae7eaf1b99ae96487601ee9ace361fd2ee249f5560fd025aa5b319570
pdf-font-stream PDF embedded font (sfnt) at offset 0xBDE2 5544 bytes
font_01_sfnt_off0000d0c9.bin
1f248c0a5fa2e2e05f4d4002f3964f4e1d9abf1be2f12b5f22fcfa2244763920
pdf-font-stream PDF embedded font (sfnt) at offset 0xD0C9 11000 bytes
font_02_sfnt_off0000f6b4.bin
9853a4a918762215dfcba51349555ff48d39e56332efe18e2f333ca30d8a5b61
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6B4 16096 bytes