Malicious PDF — malware analysis report

Static analysis result for SHA-256 c973882a9de38d8a…

MALICIOUS

PDF

110.6 KB Created: 2021-04-04 21:06:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a80f48c03138d28f0a07b6a526af03af SHA-1: 72c0751fcefee45e3ca4155666dd0c5634ae89cc SHA-256: c973882a9de38d8a2f824d8151b0c238b97f9551ef814f2ec1e3db8fcefcc7d6
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with one heuristic specifically identifying a 'link farm' intended to direct users to other PDFs. The ClamAV detection and ML classifier strongly indicate malicious intent, likely for phishing or distributing further malware. While no scripts were explicitly extracted, the PDF structure and link farm suggest an attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=18th+century+letter+folding
    • https://pupinalakarer.weebly.com/uploads/1/3/4/2/134234580/jobavosezunivo-lasaga-zusufefiwajoji.pdf
    • https://cdn-cms.f-static.net/uploads/4480582/normal_5fd8d35fd1882.pdf
    • https://wokuzavewa.weebly.com/uploads/1/3/5/3/135339714/naxewoturok.pdf
    • https://mumetimobenuja.weebly.com/uploads/1/3/2/3/132302956/7737560.pdf
    • https://sunupukub.weebly.com/uploads/1/3/5/3/135319403/90342317dc7be05.pdf
    • https://static.s123-cdn-static.com/uploads/4446917/normal_5fe54d8479f3e.pdf
    • https://cdn-cms.f-static.net/uploads/4501231/normal_5fda4454c0ac3.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://ac09d6fb-20d1-47e2-97cb-2568fc137cdf.filesusr.com/ugd/03dcd4_7ebb55ddab0e467893e6c182d6d12458.pdf?index=true
    • https://s3.amazonaws.com/nitizobuv/video_trimmer_for_windows_10_free.pdf
    • https://s3.amazonaws.com/nitatotol/best_picture_settings_for_samsung_tv_series_5.pdf
    • https://2f2ab42d-e0b4-4bd3-aa50-2430da1ff5fc.filesusr.com/ugd/eaf48f_a175c9bf453b4faf836647afcd30a92a.pdf?index=true
    • https://6bfd3344-23d3-4e03-ab7d-00c1c23eecf6.filesusr.com/ugd/be19e1_a42582ff82f54813b2aab97607048299.pdf?index=true
    • https://e905a76e-7bc1-418c-be29-e8eda1603e86.filesusr.com/ugd/3fb32a_32b671a135a44cdc852033efa2742485.pdf?index=true
    • https://s3.amazonaws.com/zomuzigo/c._h._a._o._s_helicopter_game.pdf
    • https://uploads.strikinglycdn.com/files/c073d29a-4af5-4465-86cf-205572bf5168/is_the_nespresso_aeroccino_worth_it.pdf
    • https://3568c1c9-c281-4b9a-9ea9-d5d291e0176b.filesusr.com/ugd/e5d8db_b1056ec3e7664087b7d41eaedc5af67b.pdf?index=true
    • https://uploads.strikinglycdn.com/files/37a8da41-1ca0-40a5-be2f-a7211a64a1da/o_que_fazer_quando_o_coc_entala.pdf
    • https://s3.amazonaws.com/vunizi/3771602613.pdf
    • https://uploads.strikinglycdn.com/files/72099807-1111-4647-85da-0bcebeebd5c0/which_topics_come_under_mechanics_in_physics.pdf
    • https://s3.amazonaws.com/sabegokek/marriage_anniversary_card.pdf
    • https://229c3593-bb94-4e5d-9b9f-ca3747df48ef.filesusr.com/ugd/145364_94fb86dd58d64f61bf54ec6878928ef2.pdf?index=true
    • https://uploads.strikinglycdn.com/files/b04b6d60-bed5-4165-831d-dbb69cee08e0/nifojilotew.pdf
    • https://uploads.strikinglycdn.com/files/dd31a221-5f7e-4a9c-97d5-52568acc33c8/sivokolo.pdf
    • https://a5fc3680-5c08-4cda-bd6c-abaa3bdf25bc.filesusr.com/ugd/ea5d7b_0ce3efd1b673423d804f18f611c87554.pdf?index=true
    • https://160e4e15-e27a-4ef2-9b26-f67fc0969a86.filesusr.com/ugd/cbdbb6_3f2a8aa791074432b24375aabffaff6d.pdf?index=true
    • https://8eefcaf3-52f5-4123-8be5-b1f0aaeea45e.filesusr.com/ugd/1d3654_23a9291f14214bfeb88ea85ec6fd960d.pdf?index=true
    • https://30de3caf-c510-4ce9-8691-b8280dc60d9b.filesusr.com/ugd/4980ee_0a13b4ff6183453da32bdb1e81e49cf1.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00015dd2.bin
b253a0eb29742045c38e8496bbb4ce93db02735821958d1bbf7e82d8181268aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x15DD2 5148 bytes
font_01_sfnt_off00016f63.bin
074826075d9dc487727dae8638cdd2f92ce3187d565fd6e4934ec4786cc22419
pdf-font-stream PDF embedded font (sfnt) at offset 0x16F63 11768 bytes
font_02_sfnt_off00019708.bin
541fa2b6826b0add99b7d5a173ef1e6a5567607b5192f75b810eb17d6a563501
pdf-font-stream PDF embedded font (sfnt) at offset 0x19708 16204 bytes