Malicious PDF — malware analysis report

Static analysis result for SHA-256 ebdfcff4eff7e4c0…

MALICIOUS

PDF

96.5 KB Created: 2021-03-13 15:23:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: be9f5e5b34607f803b7c225d296da023 SHA-1: 1aa890a9ad89ceecc2ea7a575742cc422bc742a1 SHA-256: ebdfcff4eff7e4c04d0c87af26b6f54c96e1a0e44039ebb49421a3cee65bffff
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, suggesting a phishing or SEO spam campaign. The ClamAV detection and ML classifier further indicate malicious intent. While no scripts were directly extracted, the PDF structure and embedded URIs are indicative of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/award?keyword=becoming+a+better+programmer+pete+goodliffe+pdf
    • http://sipipewawezizuf.getenjoyment.net/autumn_leaves_chord_melody_guitar.pdf
    • https://fovivijidilel.weebly.com/uploads/1/3/4/8/134888041/mizozisixu.pdf
    • https://vozekokojexofu.weebly.com/uploads/1/3/4/6/134645554/1aa5f23341b0d0.pdf
    • https://tujozidu.weebly.com/uploads/1/3/4/6/134694944/9222893.pdf
    • https://dazujaxika.weebly.com/uploads/1/3/1/4/131437396/8447632.pdf
    • https://static.s123-cdn-static.com/uploads/4425501/normal_5ffccc2a8b079.pdf
    • https://static.s123-cdn-static.com/uploads/4461744/normal_5ff7c2266f621.pdf
    • https://cdn-cms.f-static.net/uploads/4460466/normal_6015dadc4c8b6.pdf
    • https://vexefanakaxaki.weebly.com/uploads/1/3/4/8/134871487/277760.pdf
    • https://cdn-cms.f-static.net/uploads/4449421/normal_602027293c5b5.pdf
    • http://zememor.sportsontheweb.net/dc_motor_position_control.pdf
    • https://cdn-cms.f-static.net/uploads/4453328/normal_5fe9aae54495c.pdf
    • https://static.s123-cdn-static.com/uploads/4462339/normal_5fe5ec02b4190.pdf
    • https://static.s123-cdn-static.com/uploads/4485695/normal_6007b8757eb67.pdf
    • https://sosojisizavawov.weebly.com/uploads/1/3/1/4/131454692/8891513.pdf
    • https://cdn-cms.f-static.net/uploads/4459776/normal_603a52571908e.pdf
    • https://static.s123-cdn-static.com/uploads/4478137/normal_5ffa3cbb73fd6.pdf
    • https://cdn-cms.f-static.net/uploads/4372980/normal_60343018e0aae.pdf
    • http://kazimibi.getenjoyment.net/51036355109.pdf
    • https://neranoliva.weebly.com/uploads/1/3/4/2/134266014/vufovovinikunuf.pdf
    • https://bapajoronugenig.weebly.com/uploads/1/3/4/2/134234589/lejanoxana.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f315.bin
926bb28c509fd0802048850d650a8b0a149fe296718349e17d829e94fb7ce16b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF315 22444 bytes
font_01_sfnt_off00013b11.bin
b131c2f530d42e9535ccd3346bd301cb327d5333e2d1d63fd26f31fe9677ee17
pdf-font-stream PDF embedded font (sfnt) at offset 0x13B11 5488 bytes
font_02_sfnt_off00014d9d.bin
d30a395e1dfca5288864921a86403668722cd901e349e54bd48278cd7109fe05
pdf-font-stream PDF embedded font (sfnt) at offset 0x14D9D 11468 bytes