Malicious PDF — malware analysis report

Static analysis result for SHA-256 ddf48a3fc27655ff…

MALICIOUS

PDF

76.8 KB Created: 2021-03-30 13:20:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f7e2b958a40c6b7039b61835577f47b7 SHA-1: e6e3231bdf387c51d09e63b91e5e461e8bedc0d0 SHA-256: ddf48a3fc27655ff718f486e64a09e7d4985cd13a5e045dfa8480d40ea4cbc2e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, many of which point to suspicious domains and are part of a link farm heuristic. The document body, though heavily obfuscated, contains keywords related to educational materials, suggesting a lure to disguise malicious links. ClamAV and ML classifiers also flagged this PDF as malicious, indicating a phishing or trojan distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=grade+7+math+textbook+mcgraw+hill+pdf
    • http://ecoterritory.store/burger_king_nutrition_listfoezr.pdf
    • http://auth02mobility.com/analysis_for_financial_management_higgins_download90b19.pdf
    • http://biomaniix.website/what_is_the_most_ugly_fish_in_the_worldv61u0.pdf
    • http://hightrade.club/lukezemh5w3u.pdf
    • http://24goodstore.site/bowewikimemivabewivuwvpg77.pdf
    • http://arbitestpark.xyz/what_is_a_good_detox_smoothievabm3.pdf
    • http://indonesia2health.online/flour_water_salt_yeastr6ki8.pdf
    • http://itabody.space/bendy_in_nightmare_run_mod_apk_revdldr25v.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://5d9de69b-f80b-44d6-9c2d-9027806fef0b.filesusr.com/ugd/e26ad2_478afbb6935e4b3d812d1f7eec606cef.pdf?index=true
    • https://599b09cd-7b6a-4758-94a3-08a08d316165.filesusr.com/ugd/628a76_de2b1413536c42f59805d0a9b628c55b.pdf?index=true
    • https://6cbe2f5c-748b-4bc6-b691-25a968a47885.filesusr.com/ugd/d6b5da_fb0ab045094f4149b24849b62b683555.pdf?index=true
    • http://pawuzax.onlinewebshop.net/95175612611.pdf
    • https://f5d5bca3-0ffd-41e3-a77d-3d805a1e43e5.filesusr.com/ugd/4e23ca_a084082a1ddb43958ecc2470661147a6.pdf?index=true
    • https://63b1f34b-4847-450f-8d9a-4788d10e1cf5.filesusr.com/ugd/451a43_ff0e98c665ac4f69bc2f1e712c1fb547.pdf?index=true
    • https://s3.amazonaws.com/fukezavazuj/sony_dav-tz145_power_board_price.pdf
    • https://329f26c8-0235-4118-8622-173d264d9cf1.filesusr.com/ugd/221f3a_b07df96dc6a64973b5d59d3fe6c5c096.pdf?index=true
    • https://cf075d60-af7c-4c71-a16c-5c8c125a9bb7.filesusr.com/ugd/cc03df_8ee645209a3f4358afa9ebbb7d588f6a.pdf?index=true
    • https://s3.amazonaws.com/kuxegu/biodata_form_philippines_free.pdf
    • http://luzojora.atwebpages.com/public_administration_and_management_in_south_africa_download.pdf
    • https://s3.amazonaws.com/zurovajij/camera_fv_5_app_free.pdf
    • https://s3.amazonaws.com/sezebepit/wedgewood_rv_stove_models.pdf
    • https://71f68c9c-1037-483c-a0ca-f268b7ddd3c8.filesusr.com/ugd/87fdc7_39246c3c6edc4098af10cd8739a7c47c.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebe5.bin
f1684b1be364207625997c2620db44b9dfadb93d8aae3444c8f75e9dac3df455
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBE5 5864 bytes
font_01_sfnt_off0000ffde.bin
ce777f9458ab7a63fe50611eb147c55f45937c9775dea3b7ccd10358da1b61de
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFDE 11100 bytes