Malicious PDF — malware analysis report

Static analysis result for SHA-256 f335f9059719ceae…

MALICIOUS

PDF

84.8 KB Created: 2021-03-14 07:49:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ef5dd8e3d86704c139c8aabbefa6709f SHA-1: 92adc2596d8c983e02a1ed6c9f0ad052e8292558 SHA-256: f335f9059719ceae1799838f5ed9e871458ac2b384419ce5d27e69a82ed42857
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document was flagged by multiple heuristics as malicious, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. It contains a mass of external links, suggesting a link farm or phishing attempt, with one URL specifically pointing to a potential malware distribution point. The document body, though heavily corrupted, contains text related to game cheats, likely serving as a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=dragon+mania+tips+and+cheats
    • https://cdn.sqhk.co/norifasil/fZjbVjh/word_blitz_cheat_online.pdf
    • https://gebiworopefibo.weebly.com/uploads/1/3/4/5/134583098/9c56dff7b33db4a.pdf
    • https://jipotawa.weebly.com/uploads/1/3/6/0/136097183/8095b241a0de5ce.pdf
    • https://cdn.sqhk.co/tulotunofuz/fijcqji/74015367086.pdf
    • https://cdn.sqhk.co/fularulojoze/gg0jcja/15348491526.pdf
    • https://cdn.sqhk.co/sowotewope/lnjbXSW/mojuwexilobisegidivim.pdf
    • https://mowazaxof.weebly.com/uploads/1/3/4/7/134704653/fodefuto.pdf
    • https://cdn.sqhk.co/kelopifagisu/jiGV7BR/31197218867.pdf
    • https://selokifasafu.weebly.com/uploads/1/3/4/3/134383977/5232181.pdf
    • https://mizavujubamu.weebly.com/uploads/1/3/0/7/130775062/6872649.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://7d6e376e-1ee3-4df5-88c1-8d1511d419f8.filesusr.com/ugd/7dd30d_3f611830a33141fc944d70c57e55179f.pdf?index=true
    • https://6bfd3344-23d3-4e03-ab7d-00c1c23eecf6.filesusr.com/ugd/be19e1_5f813b4409ff41bd9d5edd5e67626341.pdf?index=true
    • https://90ff81fc-98d9-4e53-96a3-aaa5c1c2042e.filesusr.com/ugd/bb5aff_225646ccb79643f5abe37a727423ed25.pdf?index=true
    • https://s3.amazonaws.com/dojivewobasuval/zarij.pdf
    • https://s3.amazonaws.com/vuzufexarevima/avid_one_pager_templates.pdf
    • https://s3.amazonaws.com/savifin/anne_marie_friends_song_pagalworld.pdf
    • https://s3.amazonaws.com/tedowafomaru/valos.pdf
    • https://s3.amazonaws.com/kisagoz/48268613119.pdf
    • https://a49aa754-465e-4bbd-924e-b3d0e7b66bd4.filesusr.com/ugd/81d6a4_f627f6ebf5a34ec5be7ca9f69e5ec4e0.pdf?index=true
    • https://s3.amazonaws.com/wurivuve/64113451083.pdf
    • https://c809e8a6-5bdf-489d-8d8c-df4e4638a115.filesusr.com/ugd/45a296_277cfd3ce2b64971bcc2c2dc6b7020cb.pdf?index=true
    • https://d670dda7-df53-4ef1-8eda-d3256df28744.filesusr.com/ugd/dbbbec_24f8b2e46be047bc9379fbdc922606c0.pdf?index=true
    • https://s3.amazonaws.com/gotijejaj/tajur.pdf
    • https://s3.amazonaws.com/piwanisaj/java_god_of_war_game_free.pdf
    • https://a001dc82-f31e-4944-9b76-0a8e602b6855.filesusr.com/ugd/e4ee87_3516744602aa478cbc354b0053f19c43.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010d1c.bin
a88f9833ea0d453e0e8d262a5639017129631a36aed592d67435633ca2fe9e9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D1C 5452 bytes
font_01_sfnt_off00011f83.bin
bada80231c567eec08b341eaef24a7592bd68f584aae5056f66daa268d5cd287
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F83 11204 bytes