Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcd819195c5a0c09…

MALICIOUS

PDF

78.1 KB Created: 2021-03-18 13:10:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 61be94ced41998fe1c0177bc57b0c090 SHA-1: a3cd748b6e30d69444001a3a9a2a292de54496b5 SHA-256: dcd819195c5a0c091db69b2300ec5b71a64aa077ed0a39dc7b5782350999ab41
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which point to Weebly-hosted PDFs, suggesting a link farm or SEO spam campaign. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and extensive external linking are indicative of a malicious document designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=wasted+food+pdf
    • https://nobaloledajasom.weebly.com/uploads/1/3/2/6/132681012/ziseses.pdf
    • https://zusabave.weebly.com/uploads/1/3/1/4/131406295/6548449.pdf
    • https://pogiwaxo.weebly.com/uploads/1/3/5/3/135312355/3815260.pdf
    • https://kivisazof.weebly.com/uploads/1/3/2/6/132696558/7a873ac731.pdf
    • https://fovojewonot.weebly.com/uploads/1/3/4/6/134669065/vomenunik.pdf
    • https://sitavekoked.weebly.com/uploads/1/3/5/9/135974486/3103021.pdf
    • http://dawuxapi.iblogger.org/all_football_news_app.pdf
    • https://kiwepuzimogavuf.weebly.com/uploads/1/3/0/7/130776877/4705697.pdf
    • https://mufajagirudul.weebly.com/uploads/1/3/1/4/131452858/99d6df990f9b3c.pdf
    • https://wuneregogituweg.weebly.com/uploads/1/3/4/6/134686440/220aaa192.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/livivuvuwugeb/best_free_alternative_to_ms_project.pdf
    • https://s3.amazonaws.com/xarojapi/73068911256.pdf
    • https://s3.amazonaws.com/suxuzubojut/certificate_of_analysis_template_free.pdf
    • http://wafugid.epizy.com/coursera_financial_aid_answers_deep_learning.pdf
    • https://s3.amazonaws.com/zukogi/wizomaxumoperogisa.pdf
    • http://sogivuwe.onlinewebshop.net/86248234876.pdf
    • http://kagijido.myartsonline.com/levebekemi.pdf
    • http://wovibojo.onlinewebshop.net/27751298045.pdf
    • https://s3.amazonaws.com/lepefi/levutuzanajitadupig.pdf
    • https://s3.amazonaws.com/sizadagazagaj/63841794968.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f3c1.bin
e5553ae32916787357511327a516fa5b2e36e3e965c6aee7584ae461b5a8b2dd
pdf-font-stream PDF embedded font (sfnt) at offset 0xF3C1 4920 bytes
font_01_sfnt_off000104a7.bin
cd739ac0ab54377577f60f36bd24f9b7c839464d95d62c9d1e2c07fb8c099b37
pdf-font-stream PDF embedded font (sfnt) at offset 0x104A7 11376 bytes