Malicious PDF — malware analysis report

Static analysis result for SHA-256 c44fe5bcb0c16020…

MALICIOUS

PDF

98.0 KB Created: 2021-03-25 18:01:06 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: defd1c7ab82340e6aaef2268e726cb4a SHA-1: 9d70b6c2f38742ce67b6b4b938ca49a3ea957bf3 SHA-256: c44fe5bcb0c16020b01cffe4ad4dc061ab7dc205cfe522b0a1343aabde9a288d
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which point to domains that appear to be part of a link farm, as indicated by the PDF_SEO_LINK_FARM heuristic. The document body, though heavily obfuscated, suggests a lure related to search queries. The presence of ClamAV detection and ML flagging further supports its malicious nature, likely as a phishing or spam distribution tool.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=que+significa+conclusi%25C3%25B3n+en+un+trabajo+escrito
    • http://chunyoo.com/xoluburerawilepuripowud28bj.pdf
    • https://xapotitiguwux.weebly.com/uploads/1/3/4/6/134668809/nesutipuzimub-tedodefoza.pdf
    • http://optarfes.com/2012_jeep_grand_cherokee_headlight_ballast_replacement0jde7.pdf
    • http://mklhhhh.space/nursing_diagnosis_list_for_pregnancythnpd.pdf
    • http://appeal-ig.com/maus_google_drive_booksq59ch.pdf
    • https://belafawejogawol.weebly.com/uploads/1/3/4/5/134583754/8032237.pdf
    • https://vuwibisi.weebly.com/uploads/1/3/1/8/131856279/5170914.pdf
    • http://profyhouse.ru/pre_lab_report_example_chemistry5wj9q.pdf
    • http://madewithsunshine.com/what_are_the_factors_that_affect_motivation_in_second_language_learningdt8jg.pdf
    • http://lastmarkt.ru/gexovevavegabq07lt.pdf
    • http://ceter.xyz/lisinemirawiderilimufonal4lf5.pdf
    • https://dodapoxole.weebly.com/uploads/1/3/1/3/131398067/613781ee261bae6.pdf
    • https://vagomonezupu.weebly.com/uploads/1/3/4/4/134403629/redafumijipaxe-tewarituk-fosimatinuxa.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/9d188246-a2d9-419c-b481-350ea9ffcb0f/73405987582.pdf
    • https://uploads.strikinglycdn.com/files/2e5f2399-6665-47ac-b368-51480df83a23/46072167428.pdf
    • https://uploads.strikinglycdn.com/files/3990086c-244a-4b3f-8fb5-26671f13db11/no_game_no_life_season_2_episode_1_release_date.pdf
    • https://eeeff038-21f9-42a6-bde0-cd945221d618.filesusr.com/ugd/9dc459_465c1d149173447dac377346809240e8.pdf?index=true
    • https://uploads.strikinglycdn.com/files/208a2665-fcdb-40dc-ae9d-6ca1478e9f73/are_recaro_car_seats_safe.pdf
    • https://uploads.strikinglycdn.com/files/2fe40c99-aa76-4d6a-ad9b-1cc7d38447a1/bushnell_telescope_voyager_78-9930.pdf
    • https://141ebdc9-a3c9-4c6d-b8f9-366dbf139dec.filesusr.com/ugd/46bfb0_2552e385d174430da83ca79a728fe4ba.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011693.bin
0bd995ca3f350a1f2f54ab5843ce979646fb60c148eb41d3fbf504356c35e58a
pdf-font-stream PDF embedded font (sfnt) at offset 0x11693 5344 bytes
font_01_sfnt_off00012891.bin
4cdf6849a89cb36af988b76a710788b002ddd3e3a7b07888bade514c21b33d1e
pdf-font-stream PDF embedded font (sfnt) at offset 0x12891 13140 bytes
font_02_sfnt_off00015386.bin
f74ea1b10856a41706530bdcdc8b9c8cfad202a966f9a63c6c46aee3a92aa604
pdf-font-stream PDF embedded font (sfnt) at offset 0x15386 16464 bytes
font_03_sfnt_off000169bd.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x169BD 4324 bytes