Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc135892ac14de09…

MALICIOUS

PDF

136.5 KB Created: 2020-11-13 17:51:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3fa4c1b186766760d8dafeeb4136dd44 SHA-1: 59d355b07d67de9dc1ded63895d45f28e8496a30 SHA-256: dc135892ac14de09990de0e2e5b2ccbd932189547532a78dff5e717d1ca3dd05
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which point to potentially malicious domains, suggesting a link farm or phishing attempt. The ClamAV detection and ML classifier further support its malicious nature. While no scripts were explicitly extracted, the PDF structure and numerous embedded URLs indicate an attempt to redirect users to malicious content, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9723

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/123?utm_term=5th+century+bce+india
    • https://cdn-cms.f-static.net/uploads/4427509/normal_5faa3620cce4b.pdf
    • https://cdn-cms.f-static.net/uploads/4391605/normal_5f8e881c87d02.pdf
    • https://bizetuxerupa.weebly.com/uploads/1/3/0/8/130873791/3148794.pdf
    • https://vavavutexe.weebly.com/uploads/1/3/4/4/134441002/7206491.pdf
    • https://wenozujilemufo.weebly.com/uploads/1/3/4/4/134456287/pakofej-vipube-popejebikop.pdf
    • https://worozimovazez.weebly.com/uploads/1/3/1/4/131406108/4161866.pdf
    • https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/baxabusojuv.pdf
    • https://voduzivesaduv.weebly.com/uploads/1/3/4/4/134456438/9432905.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102Hussain
    • http://smc.org.inhttp://smc.org.in
    • http://www.indictrans.org
    • https://s3.amazonaws.com/petikamov/nodunirojamoli.pdf
    • https://s3.amazonaws.com/tofizo/tolirimesuv.pdf
    • https://s3.amazonaws.com/watajive/44949533266.pdf
    • https://s3.amazonaws.com/sefukirexuwekij/jareds_gallery_of_jewelry_stores_evansville.pdf
    • https://s3.amazonaws.com/bajapovogam/88246468472.pdf
    • https://s3.amazonaws.com/jobavo/unemployment_claim_illinois_sign_in.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • https://gitlab.com/smc/meera/blob/master/COPYING
    • http://sinhala.sourceforge.net/
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITS
    • http://www.gnu.org/licenses/gpl-2.0.html
    • http://scripts.sil.org

Extracted artifacts 11

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off0000e128.bin
b40bb06c2d1f0f1013d246f938cfb39fc8c6a795bc00bf188b0a43435cf35fa6
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xE128 11608 bytes
stream_010_off0001b99e.bin
b2d77454cadd7a3e0828f6ecf432833a95d743451127a027c24aa77f7b7c177a
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1B99E 25964 bytes
font_01_sfnt_off00010789.bin
3c055527da093ec08f9b6587614c88699efd50bbd456b26ba1a46877b1ae1188
pdf-font-stream PDF embedded font (sfnt) at offset 0x10789 5088 bytes
font_02_sfnt_off000118d1.bin
fc8d7356058ece1b0736d14140103031ee56c9ecf392ad196d4c78b74eb0f008
pdf-font-stream PDF embedded font (sfnt) at offset 0x118D1 3652 bytes
font_03_sfnt_off00012650.bin
fd77dcd8757e6365cd47a025bcc2bb0600cbd335f2dca187a26de80233fe9678
pdf-font-stream PDF embedded font (sfnt) at offset 0x12650 7916 bytes
font_04_sfnt_off00013fb3.bin
8fcc09f9e0e542eb98659a58b7f2598ac75eeeb48955cbc920c7ae496eb13618
pdf-font-stream PDF embedded font (sfnt) at offset 0x13FB3 5492 bytes
font_05_sfnt_off000153d6.bin
05134c60e4007699df70fc4dc683761380ca3513cc2c9218eba129b043f6f2f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x153D6 8612 bytes
font_06_sfnt_off00016ed4.bin
913659a248f779835788141c9b50b744ac8dbc1c8d4c8a15de15e1001cfd9542
pdf-font-stream PDF embedded font (sfnt) at offset 0x16ED4 4984 bytes
font_07_sfnt_off00017ed0.bin
0e1df109c38a203cab2259f09206dbae4b11ebc3b9fdd3db183907458e598891
pdf-font-stream PDF embedded font (sfnt) at offset 0x17ED0 20196 bytes
font_09_sfnt_off0001ebf3.bin
6794311c1da7878991008f20553f2d43d5b32227bbf8cc8d7ec33156a4606eda
pdf-font-stream PDF embedded font (sfnt) at offset 0x1EBF3 5216 bytes
font_10_sfnt_off0001fefc.bin
53d0d39aa151b4658490c1eb9a7f0ec74abe61dbbdb6235f627a9f5f57f483b9
pdf-font-stream PDF embedded font (sfnt) at offset 0x1FEFC 5348 bytes