Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1c84d535cfa0850…

MALICIOUS

PDF

77.9 KB Created: 2021-03-27 16:03:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7494fe29263bd9c2991c5728a1298d24 SHA-1: 11c65803129686f228faeae7fd3fe0c06b491703 SHA-256: f1c84d535cfa0850d3a8b14ca02a70e8eb9153bf5cbda753601b29207035a28d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was identified as malicious by ClamAV and an ML classifier, exhibiting characteristics of a phishing or SEO spam campaign. It contains numerous external links, including one pointing to "https://midufefew.ru/award?keyword=asthma+drugs+pdf", designed to deceive users. The PDF structure and embedded links suggest an attempt to drive traffic to malicious sites or distribute further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/award?keyword=asthma+drugs+pdf
    • https://cdn.sqhk.co/gejupajo/hfNiEP1/gewabexuno.pdf
    • https://cdn-cms.f-static.net/uploads/4405208/normal_60571710e4652.pdf
    • https://static.s123-cdn-static.com/uploads/4490974/normal_5ff0696f3aa29.pdf
    • https://xixedemawib.weebly.com/uploads/1/3/0/7/130738641/241cc2ebd86fe8.pdf
    • https://lopiranurepo.weebly.com/uploads/1/3/4/7/134735856/970577.pdf
    • https://nabebumiz.weebly.com/uploads/1/3/1/4/131452902/zegew.pdf
    • https://cdn.sqhk.co/rapovebakeb/Byigiha/pebafegutufavanalinave.pdf
    • https://cdn.sqhk.co/zalopubid/7jc9Wdj/off_road_forest_apk_dayi.pdf
    • https://cdn.sqhk.co/titabofasika/GxjaZE6/biotic_and_abiotic_components_of_ecosystem.pdf
    • https://tasusigogifu.weebly.com/uploads/1/3/5/3/135303518/pirobipos-jowesubelakese-jewege-fejap.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://f459ab6e-ac57-43ce-b83a-1524846427e4.filesusr.com/ugd/938c70_27a6b81f88c045058793d73fefacd8f9.pdf?index=true
    • https://5053e88e-9e18-4719-890c-32a1cca0295d.filesusr.com/ugd/411503_28da66c6643a470cbb00068ed14bef2c.pdf?index=true
    • https://s3.amazonaws.com/xukanomarexumu/58000652699.pdf
    • https://s3.amazonaws.com/xupimaral/92498290447.pdf
    • https://s3.amazonaws.com/bifamomove/acc_aha_guidelines_heart_failure_2013.pdf
    • https://s3.amazonaws.com/fizup/luvegixobuxejol.pdf
    • https://s3.amazonaws.com/kopisigapub/86535276552.pdf
    • https://s3.amazonaws.com/zagubip/consumer_reports_best_used_vehicles_under_20000.pdf
    • https://s3.amazonaws.com/kakef/backup_android_contacts_without_screen.pdf
    • https://c750c8cf-f189-4014-a78e-197d4cb0f9f2.filesusr.com/ugd/e5a943_e17b35f1114846a785316d9c698f2117.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f3b7.bin
70f2b4387a496b2174d24d60c99710ec919ac64072d5180c4c89f4065c016092
pdf-font-stream PDF embedded font (sfnt) at offset 0xF3B7 5412 bytes
font_01_sfnt_off000105f5.bin
9bce53877af1068bff64bf93467343fac545c3c80897c75ec94afe1218a1b749
pdf-font-stream PDF embedded font (sfnt) at offset 0x105F5 10732 bytes