Malicious PDF — malware analysis report

Static analysis result for SHA-256 c85a9727d93984f6…

MALICIOUS

PDF

69.5 KB Created: 2021-03-25 08:32:37 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a65dacdd81445b7debcd21dfd60f639e SHA-1: 24d65fe0fb54c4285f674ebe2d454b608408f12f SHA-256: c85a9727d93984f6a5fa71a636d50f961f4d5c13ccbb006da8bf55a091069b7e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was identified as malicious by ClamAV and an ML classifier, exhibiting characteristics of a link farm. It contains numerous external links, suggesting an attempt to manipulate search engine results or redirect users to potentially malicious content. While no scripts were directly extracted, the PDF structure and the presence of many external links indicate a likely phishing or SEO spamming attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9145

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/award?keyword=spherical+roller+thrust+bearing+catalogue+pdf
    • https://cdn-cms.f-static.net/uploads/4485714/normal_603e08af194da.pdf
    • https://gijojipile.weebly.com/uploads/1/3/1/3/131381352/875698.pdf
    • https://cdn.sqhk.co/suwezuzifu/DyTjgnn/phoenix_weather_october_average.pdf
    • https://cdn-cms.f-static.net/uploads/4380857/normal_60112878bb321.pdf
    • https://nanarimedut.weebly.com/uploads/1/3/2/6/132695535/a0511.pdf
    • https://cdn.sqhk.co/zolewiko/gjNiahw/classic_prototype_racing_2.pdf
    • https://rirejanumaxix.weebly.com/uploads/1/3/4/6/134631236/36051ac101.pdf
    • https://kigovedinefetup.weebly.com/uploads/1/3/1/3/131384362/silamoza.pdf
    • http://kogovokuriboti.22web.org/amiga_forever_android_apk.pdf
    • http://nujanafuvasas.iblogger.org/37708920163.pdf
    • https://cdn-cms.f-static.net/uploads/4451021/normal_605a44d6d37e1.pdf
    • https://cdn.sqhk.co/furabafezuse/sjjxcEi/f1_game_ps_vita.pdf
    • https://vetolotex.weebly.com/uploads/1/3/1/3/131379132/7612558.pdf
    • https://vulefewaxamovu.weebly.com/uploads/1/3/3/9/133997320/6392899.pdf
    • https://tujurexi.weebly.com/uploads/1/3/4/7/134743655/kegejapagijo-dilamagera-tefezepivofaku.pdf
    • https://vinokiwofexuge.weebly.com/uploads/1/3/6/0/136095936/farilot_ravaba_zujeluvudowepa.pdf
    • https://bubipirem.weebly.com/uploads/1/3/6/0/136086135/cfea697.pdf
    • https://piwusobalusuwav.weebly.com/uploads/1/3/2/3/132303181/3158f1f8.pdf
    • https://wigikeketiru.weebly.com/uploads/1/3/1/4/131406435/431b8c57444.pdf
    • https://static.s123-cdn-static.com/uploads/4383566/normal_5fce1171d3e0c.pdf
    • http://lulelil.22web.org/kesagav.pdf
    • https://static.s123-cdn-static.com/uploads/4451561/normal_60091216a075e.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zefobik.epizy.com/gesonobisopebabigudopiv.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e04c.bin
5f78f61d65de8d26be3ea232ced6a66869e2b38ea3c55e716371f4e3c3dd6424
pdf-font-stream PDF embedded font (sfnt) at offset 0xE04C 5660 bytes
font_01_sfnt_off0000f380.bin
284902b56604d0dea592b30be1351f480fe64008f06bd37a6c4faa39813e4f7c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF380 10808 bytes