Malicious PDF — malware analysis report

Static analysis result for SHA-256 c66ee0d8ca852c14…

MALICIOUS

PDF

76.7 KB Created: 2021-06-10 18:11:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b41e6aa6f927eccd091e1b253199afd0 SHA-1: dc7914cadf346caa7da8600ae0c2663072e0f786 SHA-256: c66ee0d8ca852c14288cf80adff61a925a091b4f7a25b3b56d67a392321a718d
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to Weebly-hosted PDFs, suggesting a link farm or redirection mechanism. The heuristic 'PDF_SEO_LINK_FARM' and the presence of multiple external URIs indicate a malicious intent to direct users to potentially harmful content. The ClamAV detection and ML classifier further support its malicious nature, likely as a phishing or malware distribution tool.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/123?utm_term=bachelor+degree+in+information+technology+courses
    • https://nabebumiz.weebly.com/uploads/1/3/1/4/131452902/bupinaresatomor.pdf
    • https://nudijezomuxu.weebly.com/uploads/1/3/4/3/134377325/vovopotusox.pdf
    • https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/39993515c62a0e.pdf
    • https://kagesurofuzesik.weebly.com/uploads/1/3/5/3/135303772/terazigusurusiroruf.pdf
    • https://cdn-cms.f-static.net/uploads/4478664/normal_604f65ad300fd.pdf
    • https://cdn-cms.f-static.net/uploads/4498330/normal_601cbab45d9c1.pdf
    • https://cdn-cms.f-static.net/uploads/4401525/normal_606d4c07b7faf.pdf
    • https://wutiboduselojo.weebly.com/uploads/1/3/4/6/134665342/waribat_dovedem_rifugafiwejov_tadoju.pdf
    • https://lijasefevofik.weebly.com/uploads/1/3/4/8/134889997/295784.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://dojejezo.pbworks.com/f/52803408272.pdf
    • https://uploads.strikinglycdn.com/files/a165f0ae-78ef-4c0a-93db-1223eab51ca4/40278015193.pdf
    • https://uploads.strikinglycdn.com/files/dc03ed74-4154-41ed-8ff1-b2ae0debeb21/fifadetoji.pdf
    • https://uploads.strikinglycdn.com/files/07f05339-7135-443f-96ca-1beceb747ce5/xidabasujisizu.pdf
    • https://uploads.strikinglycdn.com/files/b184f693-42e5-47ef-9d94-0c09a5ee96e8/computer_programming_job_degree.pdf
    • https://uploads.strikinglycdn.com/files/f50e8723-d125-42bb-9df6-4ff0370c01e1/probability_book_for_bsc.pdf
    • https://uploads.strikinglycdn.com/files/6aeeb091-ee6c-4201-b427-82d0212e61a1/kabesuz.pdf
    • http://metudebebi.pbworks.com/f/xulalabogubu.pdf
    • http://kolasotosexu.pbworks.com/w/file/fetch/144415323/fivatigadir.pdf
    • https://uploads.strikinglycdn.com/files/fa9f7a8f-e6db-4d74-a666-8527cbc59197/miwopekudajimal.pdf
    • https://uploads.strikinglycdn.com/files/aa7ca158-d9ac-40f3-9471-49dc925e0f7a/rational_numbers_word_problems_worksheet_grade_7_with_answers.pdf
    • https://uploads.strikinglycdn.com/files/9482a456-d228-40ef-8bb0-eea9244e9008/jebonovemetuligepolobis.pdf
    • http://morabef.pbworks.com/f/wujidubezupotewonutixufe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eae8.bin
77cf5b37e0447a59d7f484cb30398334055f593cb00c50ca671716d03829360f
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAE8 5584 bytes
font_01_sfnt_off0000fdc9.bin
fa3d7475a0f4a6b631976e674af1f34468210964dfe89f75bf2c0607104f35d3
pdf-font-stream PDF embedded font (sfnt) at offset 0xFDC9 11300 bytes