Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6846ec2f1f64ac8…

MALICIOUS

PDF

69.2 KB Created: 2021-06-11 20:08:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: ba69109cf2821a6ec3b0ed829ddb87b3 SHA-1: a9b41a3c28bc7ca8a5a86c2c1b442f4f9f8ebac3 SHA-256: d6846ec2f1f64ac81ce79693d2fe6188b004a560dbe5fb8bc3c4b54eefff2b5e
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a significant number of external links, identified as a link farm. The primary external URL, https://huntic.ru/pbw?utm_term=lightning+staff+code, suggests a potential phishing or SEO manipulation tactic. While no scripts were extracted, the PDF structure and heuristic firings strongly indicate malicious intent, likely to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://huntic.ru/pbw?utm_term=lightning+staff+code PDF link annotation
    • https://bubawupuga.weebly.com/uploads/1/3/4/3/134380130/silaw.pdfIn PDF document text
    • https://pizakatunif.weebly.com/uploads/1/3/1/8/131856177/kefakifezifus-ratavalafujof.pdfIn PDF document text
    • https://gexuganogos.weebly.com/uploads/1/3/0/8/130813630/4659866.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/a32dae30-e7e5-4181-beb9-145848758e1e/do_punching_bags_help_you_fight.pdfIn PDF document text
    • http://zobifel.pbworks.com/w/file/fetch/144616170/cracked_netflix_apk_ios.pdfIn PDF document text
    • http://legesir.pbworks.com/w/file/fetch/144742290/89583654308.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d6965b7d-f845-4954-954c-7d0b4512689e/what_are_metabolic_renewal_exercises.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/95d6a085-eb05-47bd-9ebb-92ec9f542ae9/what_is_an_example_of_a_literary_allusion.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1c323151-b54e-4985-a70c-3effa74d4add/cade_simu_3.0_portugues_download_completo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3f585542-a34c-4c2f-a8ac-3464d5d64a6f/samajipiguwazegidivibewa.pdfIn PDF document text
    • http://xojifot.pbworks.com/f/internet_connection_cancellation_letter_format_in_word.pdfIn PDF document text
    • http://mugobug.pbworks.com/f/war_robot_download_apk.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9d125bab-4aa8-42db-816e-507b62d06474/mupidelulekaj.pdfIn PDF document text
    • http://sutodoromar.pbworks.com/w/file/fetch/144518784/how_to_schedule_bulk_trash_pickup.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/291618df-7678-43f1-beb9-8be71ddbd6e7/a_single_man_movie_quotes.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/65e1913b-d661-46e7-a73b-70ac84224561/macbeth_script_act_2_scene_2.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/71615573-c338-481d-9c77-67ee74803b5b/goflex_home_lost_password.pdfIn PDF document text
    • http://zewalar.pbworks.com/w/file/fetch/144472887/65473904418.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2a659200-9c15-40fd-8a16-54fc20b88b31/mardaani_full_movie_download_hdfriday.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d137.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD137 5096 bytes
SHA-256: b8482b990891d172cb352b48b1b6c2f9b7c2c5a7c87d6b2d49f739357369a0f1
font_01_sfnt_off0000e29a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE29A 10604 bytes
SHA-256: ae4ed86cc1a19da3b0ac83b616916107c1dd46c9caecca0d55289c78c199a1c2