Malicious PDF — malware analysis report

Static analysis result for SHA-256 c45a63780faa3066…

MALICIOUS

PDF

81.0 KB Created: 2021-03-23 10:08:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3d8a06000934dabe314ae8cdd104915a SHA-1: bd0b0aafdee2eecde6951019db4d0c61c46e8554 SHA-256: c45a63780faa30661549f93311469d104bd5f212bad593e5f7edbc1c77ede82a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a significant heuristic firing indicating a link farm designed to distribute SEO-poisoned content. The ML classifier and ClamAV detection strongly suggest malicious intent, likely for phishing or malware delivery. While no scripts were directly extracted, the PDF structure and heuristic firings point towards the use of embedded JavaScript to facilitate redirection to malicious URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/wix?keyword=evaluating+limits+worksheet+with+answers
    • http://icub.tech/xcom_enemy_unknown_android_gameplaytd01n.pdf
    • http://merishwheelrecords.com/tozb5.pdf
    • https://buzelobuledu.weebly.com/uploads/1/3/1/3/131397981/4168959.pdf
    • http://itverys.space/vosuz9xwxs.pdf
    • https://fedalovojuxunod.weebly.com/uploads/1/3/0/7/130775560/nokevoviw-mubofurudunox-gekujutevipo.pdf
    • http://argo-tourism.com/gorajetabugalie6fs4.pdf
    • http://wide-take.top/which_piano_is_best_for_beginnersi5o1y.pdf
    • https://tarimewisu.weebly.com/uploads/1/3/0/7/130739021/doxikese-refikukuvadud-pagol-sezefidevusun.pdf
    • http://help-ruleviolation.com/30474765819m66cl.pdf
    • http://alisaborodaenko.design/81502006996sn5ev.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://35479656-6a94-44d6-ac55-da507c14a2ae.filesusr.com/ugd/d68318_2254c63bd17e43798eb863f4bbec9b9a.pdf?index=true
    • https://5ce19dfa-329f-495d-88d1-e1e7834d9072.filesusr.com/ugd/d902bb_372b4ed444f645d898782d086ef8d696.pdf?index=true
    • https://e8c82854-2a0b-4c0f-82de-bac600ce06e6.filesusr.com/ugd/d017d5_f4abdda6dbb946b1a9ea7d747bc17764.pdf?index=true
    • https://s3.amazonaws.com/jivagajamav/last_cloudia_reroll_guide_bluestacks.pdf
    • https://s3.amazonaws.com/mixanaz/bootable_windows_7_iso_free.pdf
    • https://uploads.strikinglycdn.com/files/cf0f1705-100a-4265-ad15-2e011a442bc2/85335748395.pdf
    • https://uploads.strikinglycdn.com/files/374a7c9a-d210-4fcc-b3cf-14ab01ca29c6/does_table_salt_have_healing_properties.pdf
    • https://uploads.strikinglycdn.com/files/25bc7dfc-4dbb-424c-a57d-1048a7cc3f18/enseanza_del_caballero_de_la_armadura_oxidada.pdf
    • https://s3.amazonaws.com/jenisozazewubo/one_piece_bounty_rush_apk_2019.pdf
    • https://s3.amazonaws.com/lulelepese/nasibipotinizam.pdf
    • https://uploads.strikinglycdn.com/files/3bbc2f37-ad0b-44ef-997f-56bdd00516fc/windows_7_operating_system_tutorial_free_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e5fb.bin
562c50642e8905750c7abfc67a4e1c63a366c537404057bb9e2dd7a54354b023
pdf-font-stream PDF embedded font (sfnt) at offset 0xE5FB 5272 bytes
font_01_sfnt_off0000f7d6.bin
131d5ff3723609788e1b2d2b497d15b7e9b53f018a8064383fdec84867cc6cb6
pdf-font-stream PDF embedded font (sfnt) at offset 0xF7D6 11332 bytes
font_02_sfnt_off00011f14.bin
b1345b03cb8ff90cb42c7c8f61cc0a97610ec8082568e26930ee59dd54284444
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F14 16236 bytes