Malicious PDF — malware analysis report

Static analysis result for SHA-256 f05dd87117400f2d…

MALICIOUS

PDF

73.6 KB Created: 2021-02-24 00:45:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c5b30d48d1d733fcf5ef92e4a234c436 SHA-1: 1068c7edfbbf48bdfe2c7db4c551a7b444123fbc SHA-256: f05dd87117400f2d719efb77491b9fbf03500d589558c7fe38514aa51fdd2e53
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, identified as a link farm, which is a common technique for SEO manipulation or distributing malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or trojan delivery. No scripts were extracted, but the presence of numerous external URLs suggests a phishing or content-luring attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=normans+and+saxons+kipling
    • http://gopagagoraxu.22web.org/how_to_set_up_a_coleman_hot_tub.pdf
    • https://cdn.sqhk.co/ninoporaleva/gjfgfWj/pdf_reader_viewer_apk_download.pdf
    • http://zezitil.22web.org/mac_foundation_colour_guide.pdf
    • https://bifomika.weebly.com/uploads/1/3/1/8/131856700/samebirozife.pdf
    • https://cdn-cms.f-static.net/uploads/4417986/normal_600e4cd4c018e.pdf
    • https://gososeru.weebly.com/uploads/1/3/4/5/134597059/zemunitofewelozopori.pdf
    • https://biwomewiwuxe.weebly.com/uploads/1/3/4/1/134131409/wetavafivedolifeka.pdf
    • https://dapasubasawesol.weebly.com/uploads/1/3/4/3/134383907/6579363.pdf
    • https://xulavuxedipi.weebly.com/uploads/1/3/4/0/134017657/227ded59e3f10d5.pdf
    • http://putijeku.22web.org/nabeponiloxirip.pdf
    • https://bipufufutugudov.weebly.com/uploads/1/3/1/1/131164095/951655.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e3fa.bin
dc5be833896c8041e35dd51918f48be2753df049751484d2c93a788859f24b07
pdf-font-stream PDF embedded font (sfnt) at offset 0xE3FA 5380 bytes
font_01_sfnt_off0000f634.bin
d84fb152130754a38aa9714eff8da8639522e3e5ee3a9f83c6a27f7e7d640324
pdf-font-stream PDF embedded font (sfnt) at offset 0xF634 10492 bytes