Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6d3948318e50923…

MALICIOUS

PDF

99.9 KB Created: 2021-05-31 05:46:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 36978951dd0cc6192d928f7047037d94 SHA-1: 787915d8192e911e9f95df968b91304478c1d358 SHA-256: d6d3948318e50923578f51ea2f3be012ecc46b87d487ff828771dea8accc05bf
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are generated in a way that suggests a link farm for SEO purposes, with some pointing to potentially malicious domains. The presence of urgency language further supports a phishing or malicious redirection attempt. ClamAV and ML classifiers also flagged this PDF as malicious, indicating a high likelihood of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=how+long+does+fcra+background+check+take
    • https://valefeka.weebly.com/uploads/1/3/5/3/135345526/fumowajazivezej-suleweve-matixepi-vitusu.pdf
    • https://cdn-cms.f-static.net/uploads/4496165/normal_600bc81e35e46.pdf
    • https://cdn-cms.f-static.net/uploads/4410190/normal_5fd1573142920.pdf
    • https://robevumike.weebly.com/uploads/1/3/4/7/134767989/samigopigor.pdf
    • https://vulajavup.weebly.com/uploads/1/3/4/6/134683256/wawavunewebu_tavafowonilu_zibitir.pdf
    • https://fepaxumezo.weebly.com/uploads/1/3/4/3/134320712/9725903.pdf
    • https://lonawapusar.weebly.com/uploads/1/3/0/7/130776864/742620.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/e37ccfb9-5855-4a6e-89f7-ddb8edd1c3aa/all_american_921_pressure_canner_for_sale.pdf
    • https://uploads.strikinglycdn.com/files/367f820b-2be9-4be2-8b82-f154f3dbd52d/fofudoxozami.pdf
    • https://uploads.strikinglycdn.com/files/5f61a1dd-584b-4f4c-be43-7cb4fa134607/garmin_405_watch_strap.pdf
    • https://uploads.strikinglycdn.com/files/3c07e22c-0808-47cb-8af8-06096f47fcb9/12847415662.pdf
    • https://uploads.strikinglycdn.com/files/06b3107a-b351-41d4-92fa-aebd881965cf/9975984945.pdf
    • https://uploads.strikinglycdn.com/files/8abfee4b-b540-4827-b881-8ae0fad52664/lorugepod.pdf
    • https://uploads.strikinglycdn.com/files/2a158ac1-7e69-4b50-bc29-bdc83f2dedee/xotewosudezubutiwixafobos.pdf
    • https://uploads.strikinglycdn.com/files/9d222b05-f52e-4eaf-bb82-7844173bc2a3/xerox_workcentre_3325_reset_admin_password.pdf
    • https://uploads.strikinglycdn.com/files/dc79a9e7-ce69-4f01-bed0-72142d1e2d87/jafimasipobirefiv.pdf
    • https://uploads.strikinglycdn.com/files/edc3e67d-6389-4ac7-a886-efd20fb0e9ab/oshenwatch_app_for_iphone.pdf
    • https://uploads.strikinglycdn.com/files/0f04a2cb-0d73-4908-b1b0-0fcccd09c161/james_joyce_araby_theme.pdf
    • https://uploads.strikinglycdn.com/files/c4dfe9c7-a789-4d2c-a005-7ff34c926fc4/56080283216.pdf
    • https://uploads.strikinglycdn.com/files/ca734ebf-af07-49cc-bf8d-5e509a9a3499/22251389691.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001476c.bin
916e3b9394b2e99a985941d16d0afd4d3c38ff937282d4c484ad3dbb71f7a040
pdf-font-stream PDF embedded font (sfnt) at offset 0x1476C 5540 bytes
font_01_sfnt_off00015a54.bin
a813d55a3bcdba6afab57efa1ef93562841efdb5292401ff346b0386a961a315
pdf-font-stream PDF embedded font (sfnt) at offset 0x15A54 11180 bytes