Malicious PDF — malware analysis report

Static analysis result for SHA-256 f164135d381b22be…

MALICIOUS

PDF

85.1 KB Created: 2021-03-20 22:09:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3467f447cd106808f0357980126107fa SHA-1: d7053a6d370249672b492259c5cdaf9f67fade8b SHA-256: f164135d381b22be2f452faa6c5c79d5dfaf9d1a1ee92ad727331108e1c4764f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, suggesting a malicious intent to redirect users. The presence of ClamAV and ML heuristics flagging it as malicious, along with multiple unknown reputation URLs, reinforces this assessment. While no scripts were explicitly extracted, the PDF structure and link farm indicate a likely attempt to lead users to phishing or malware distribution sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=blacksmith+guide+ragnarok+mobile+reddit
    • https://zuvopejibi.weebly.com/uploads/1/3/4/0/134017525/negivuletusabiseloj.pdf
    • http://fartook.online/kansas_gas_service_new_service7qo7b.pdf
    • http://mydenverneighborhoods.com/practice_problems_in_mendelian_genetics_worksheet_answerstcepn.pdf
    • https://xavujome.weebly.com/uploads/1/3/0/7/130739328/liwoxudamalefora.pdf
    • https://gulekizusivo.weebly.com/uploads/1/3/5/3/135392766/piwofusokakeb.pdf
    • http://circus.market/2001_mitsubishi_montero_sport_ownersujtx7.pdf
    • http://zdorovienashevse.xyz/lurozibexisuxa542zn.pdf
    • https://pusuwane.weebly.com/uploads/1/3/5/3/135346572/wopuzu.pdf
    • http://ooovseanalizi.ru/stalking_can_be_defined_as_haven_answersswij8.pdf
    • https://bufuxilanu.weebly.com/uploads/1/3/4/4/134402831/vaxoj.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.opentle.org
    • https://s3.amazonaws.com/fizup/baby_shower_memory_game_free_template.pdf
    • https://uploads.strikinglycdn.com/files/feaa5f9e-154b-4e7d-b099-b2d9de7f4b3c/57372942006.pdf
    • https://s3.amazonaws.com/kasuwevovog/business_partnership_agreement_template_uk.pdf
    • https://uploads.strikinglycdn.com/files/a42ce980-bc87-44ac-8fcb-ba6f85850c06/what_period_was_pride_and_prejudice_written_in.pdf
    • https://s3.amazonaws.com/lorifawuvawot/49859307377.pdf
    • https://s3.amazonaws.com/telasebisu/5389857719.pdf
    • https://s3.amazonaws.com/kosamupim/skyrim_legendary_creation_kit.pdf
    • https://s3.amazonaws.com/bejexe/notice_of_resignation_letter_template_uk.pdf
    • https://s3.amazonaws.com/fajixe/42622338686.pdf
    • https://s3.amazonaws.com/pevarijidasalop/vufaviboluzuravagetu.pdf
    • https://uploads.strikinglycdn.com/files/8040f97e-36aa-40af-a4bb-6956766f1aff/xuruvitar.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e383.bin
8d3974826ccfaafb721dc7908d3d943def875a323c67c89da4d019d7518981e4
pdf-font-stream PDF embedded font (sfnt) at offset 0xE383 5788 bytes
font_01_sfnt_off0000f771.bin
c2ce984730495ff7c0b8a16dcffd248bfcd1032feacf530c6181715c3f54d2e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF771 5604 bytes
font_02_sfnt_off00010a46.bin
d244c6a9f40b9ab9777ff4c3573026e5e887e9e0880a8214647908aa709e84bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A46 9448 bytes
font_03_sfnt_off00012450.bin
63ba821a4e5c2cd34571ca7bd03bf30b6bcf3a835d5862288a350c81e616edd9
pdf-font-stream PDF embedded font (sfnt) at offset 0x12450 9824 bytes