Malicious PDF — malware analysis report

Static analysis result for SHA-256 f37a7e50f20d87b7…

MALICIOUS

PDF

77.5 KB Created: 2021-03-26 09:31:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 196a84cd383754329da15ce91e580168 SHA-1: 12f3a57f03c146b83af4c1f3e1704f4d3ebde1e9 SHA-256: f37a7e50f20d87b7d488489f7c783621d2def2f5da1d5f717e0f1f6aa5aa683a
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which point to PDF files hosted on various domains, suggesting a link farm or phishing attempt. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and numerous external links are indicative of a phishing or malicious redirection scheme, likely leveraging embedded JavaScript for obfuscation or redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8528

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/award?keyword=concierto+de+aranjuez+trumpet+solo+pdf
    • https://betetaguzom.weebly.com/uploads/1/3/2/3/132303315/ludedumeduko-tajewi.pdf
    • https://xinagaxigivawiv.weebly.com/uploads/1/3/0/7/130739766/risivo.pdf
    • http://fitnesspack.net/what_is_the_main_focus_of_technical_writing_aimed_at_a_non-technical_audiencebgfpu.pdf
    • https://binigikuvoloxog.weebly.com/uploads/1/3/5/3/135332024/momukavexupa.pdf
    • http://prizinsta365.site/how_to_pronounce_boy_in_hebrew8b52y.pdf
    • https://cdn-cms.f-static.net/uploads/4486045/normal_60358a321d7e5.pdf
    • https://sekikeke.weebly.com/uploads/1/3/4/7/134739811/wunadivibolub_naxekawalawa.pdf
    • http://suniduno.iblogger.org/cuneiform_bone_fracture_icd_10.pdf
    • https://nikatomorufaxeg.weebly.com/uploads/1/3/1/4/131437252/1691977.pdf
    • http://study-english-02.space/4886593070z83ug.pdf
    • https://cdn-cms.f-static.net/uploads/4496001/normal_601d9eff70780.pdf
    • https://ritipovilij.weebly.com/uploads/1/3/4/6/134650849/xevezaxuxaxij_zewugotadij.pdf
    • https://ragadavifomo.weebly.com/uploads/1/3/5/3/135306528/9513051.pdf
    • http://interstart.online/16316784386jplwj.pdf
    • https://xufalawat.weebly.com/uploads/1/3/0/8/130814535/todazurojiriwodemapa.pdf
    • http://italywow.space/81520932936nle0c.pdf
    • http://50off.pro/bass_guitar_sheet_music_freeokuyh.pdf
    • http://xezimev.22web.org/27733459214.pdf
    • http://lnstagramcopyrightcenter.com/449277153892rao0.pdf
    • http://get3creditscores.info/4766796475910d7w.pdf
    • https://kodabovoxalomas.weebly.com/uploads/1/3/5/3/135340354/a613741.pdf
    • https://vinovubetiloj.weebly.com/uploads/1/3/4/6/134679092/xofowujumebege.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://jedenibiripo.epizy.com/40195683595.pdf
    • http://tejoratu.epizy.com/class_11_physics_lab_manual_solutions.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010132.bin
6898c0bd4ea9829a10614324d2d6cd545b7bf9d85f0ca08da7f97a81ee153dc4
pdf-font-stream PDF embedded font (sfnt) at offset 0x10132 5332 bytes
font_01_sfnt_off00011347.bin
e310ab583398d943315a63379d4b4ee13c2785c571846a432887f8bc3bd18118
pdf-font-stream PDF embedded font (sfnt) at offset 0x11347 12560 bytes