Malicious PDF — malware analysis report

Static analysis result for SHA-256 c864c220d1de5fba…

MALICIOUS

PDF

68.1 KB Created: 2020-11-25 22:13:08 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f3f164c15e21c574e7b635c6ce5dc5c5 SHA-1: 6c92f7ed7a5e18205689c6e6543dd831f9b64168 SHA-256: c864c220d1de5fba249151bfa7aec610b79b3bd8430341b22b3bfcfe0d0685c4
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV and an ML classifier, with critical heuristics indicating it's a phishing/trojan PDF and contains a link farm. The embedded URL points to a suspicious domain, likely used for phishing or to host further malicious content. Although no scripts were explicitly extracted, the PDF structure and heuristics suggest an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/strik?utm_term=oxygen+concentrator+repair+manual
    • https://mepafuxutare.weebly.com/uploads/1/3/4/6/134660934/1816054.pdf
    • https://kivuligob.weebly.com/uploads/1/3/0/8/130874143/zozetexojepav.pdf
    • https://cdn-cms.f-static.net/uploads/4375203/normal_5f9a5dad3164a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/e56ae037-09b4-4a10-a97a-fce33afd8b71/numro_d_immatriculation_arret_de_travail.pdf
    • https://uploads.strikinglycdn.com/files/aa53e535-d6c1-48ac-8de4-61d9b738eaa0/37268342982.pdf
    • https://uploads.strikinglycdn.com/files/7a2afa95-fc6d-4f13-b4a0-4348655ac49b/90990211127.pdf
    • https://s3.amazonaws.com/fujadabez/bsa_first_class_requirements_worksheet.pdf
    • https://s3.amazonaws.com/wibadinavosunom/putaziximop.pdf
    • https://s3.amazonaws.com/wukevirenesu/83955041003.pdf
    • https://s3.amazonaws.com/tulosa/apache_helicopter_attack_video.pdf
    • https://uploads.strikinglycdn.com/files/c5c783a7-066b-4ebe-875d-85334235f893/patezi.pdf
    • https://s3.amazonaws.com/juliziwojatige/seacoast_bank_bonus.pdf
    • https://uploads.strikinglycdn.com/files/e68f0bac-23bc-4cbc-b7fd-c80130529668/bridesmaids_flight_clip.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cd17.bin
acf6b083d0f32bde790fb306e461c36e2cab81fd77714d0444bec3cf17c7c2a4
pdf-font-stream PDF embedded font (sfnt) at offset 0xCD17 5272 bytes
font_01_sfnt_off0000df04.bin
87517fb05c55e1cc721d249c1c467566906e75b6ca70a4686229742d356bec96
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF04 10736 bytes