Malicious PDF — malware analysis report

Static analysis result for SHA-256 def7f6df672708c5…

MALICIOUS

PDF

75.4 KB Created: 2021-03-31 15:27:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a557c3bb65707b790fc4160d1e9c1a3d SHA-1: 28ec4aa3d33063c639a7265ca8e1f90178cd026d SHA-256: def7f6df672708c5f6369cd838b6839506b565222fe3f2bf1474ce1d858158e3
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics and an ML classifier as malicious, with ClamAV identifying it as a phishing trojan. The PDF contains a large number of external links, indicating it functions as a link farm. The primary malicious activity observed is the embedding of numerous URLs, likely intended to redirect users to phishing sites or download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=acm+racs+2017
    • https://mepapezivodeno.weebly.com/uploads/1/3/0/9/130969154/d036c79.pdf
    • https://dunifavopugi.weebly.com/uploads/1/3/5/3/135312205/nawupijosevumi.pdf
    • https://cdn.sqhk.co/zotipimesaza/gficPgj/pdf_to_word_conversion_online_zamzar.pdf
    • http://bulakirip.getenjoyment.net/encyclopedia_of_drawing_techniques.pdf
    • https://cdn.sqhk.co/waxobakal/dUcBifu/vudexapokavesoge.pdf
    • https://cdn.sqhk.co/vimewiki/tPjiDif/slime_smash_diy_slime_fidget_slimy_mod_apk.pdf
    • https://darojavanobize.weebly.com/uploads/1/3/4/8/134889586/nukigumisa-lasixaxiv-jesexogu.pdf
    • https://wikabolodaj.weebly.com/uploads/1/3/4/6/134648749/tukizuwegomitek.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/357c53f7-ed1a-4352-804b-12731436f0b8/wudufixut.pdf
    • https://uploads.strikinglycdn.com/files/a4e594b8-d766-4204-b23b-b9f820735098/43807588539.pdf
    • https://uploads.strikinglycdn.com/files/2e74aa8c-10ec-457d-8107-0f2eb7267313/99755393790.pdf
    • https://uploads.strikinglycdn.com/files/14e8366c-6255-4b1d-bc9d-cb7f265a1fca/how_to_get_license_for_sketchup_pro_2018.pdf
    • https://uploads.strikinglycdn.com/files/1448184b-0077-4794-b05f-5c4193a4128b/how_to_read_case_numbers.pdf
    • https://uploads.strikinglycdn.com/files/d1cf80f1-80a4-462a-a2da-e3abc59bb302/the_merchant_of_venice_2004_full_movie.pdf
    • https://uploads.strikinglycdn.com/files/11f571fe-f0dc-492d-9895-9ebe26a2bbbb/zoom_h4n_mic_level.pdf
    • https://uploads.strikinglycdn.com/files/0029aef6-37cf-4e24-b5ec-4d2367cb4a2e/roblox_clown_kidnap_command.pdf
    • https://uploads.strikinglycdn.com/files/8df9e9ef-1408-4c68-8105-cac006022482/28604446443.pdf
    • https://uploads.strikinglycdn.com/files/ecc28431-9d2b-4ea1-8c9d-99447615d4dd/60936281416.pdf
    • http://mifotabelimudon.myartsonline.com/xosaxinodipupo.pdf
    • http://sites.google.com/site/acmrac
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8d5.bin
472e1866355b14e57d063a0388a94c814226af1049b5eae5dbd457077d3a8fa5
pdf-font-stream PDF embedded font (sfnt) at offset 0xE8D5 5308 bytes
font_01_sfnt_off0000fad1.bin
d6c2ed770a303523a8d0933f959a134a1032df18996f306e719cb193c3517dc7
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAD1 11056 bytes