Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3d63ce9678e4980…

MALICIOUS

PDF

86.6 KB Created: 2021-03-16 16:10:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 31dee33417d222de83e3dfda13dd0daa SHA-1: 93ce81b5544bb27b2a3915e2ac9727a4b82a6a1a SHA-256: f3d63ce9678e4980deab6f0f4784a31beb9834bfc7e147269d6d7b5901384ca5
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics, including PDF_SEO_LINK_FARM and ML_NYX_PDF_MALICIOUS, indicating a high likelihood of malicious intent. The presence of numerous external links, many pointing to Weebly and S3-hosted PDFs, suggests a link farm designed to distribute malicious content or phish users. Although no scripts were explicitly extracted, the PDF structure and link farm indicate an attempt to redirect users to malicious sites, likely for malware distribution or phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/123?utm_term=lagu+aint+nobody+takin+my+baby PDF link annotation
    • https://vebilikowuti.weebly.com/uploads/1/3/2/7/132740371/fd0933345b98.pdfIn PDF document text
    • https://cdn.sqhk.co/mejofiwog/hjibwWV/strategy_meaning_in_urdu_sentence.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4495254/normal_5ff57bd24ebaf.pdfIn PDF document text
    • https://cdn.sqhk.co/tajiwikiter/Mhb5J7K/68944915729.pdfIn PDF document text
    • https://cdn.sqhk.co/dodipenameki/jbhcibP/gce_o_level_format_english_report_writing.pdfIn PDF document text
    • https://kukevukoleguko.weebly.com/uploads/1/3/4/2/134265740/5f36939d4769950.pdfIn PDF document text
    • http://websporizle4.com/how_to_hustle_and_win_2uu0wu.pdfIn PDF document text
    • https://cdn.sqhk.co/datolabevev/rbgjMjM/72329154439.pdfIn PDF document text
    • https://pobivizitonep.weebly.com/uploads/1/3/2/8/132815986/2449193.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4461250/normal_5fe4ed636467d.pdfIn PDF document text
    • https://fovivijidilel.weebly.com/uploads/1/3/4/8/134888041/7230009.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369651/normal_5fd73b48cf8c5.pdfIn PDF document text
    • https://laguwiba.weebly.com/uploads/1/3/4/7/134719839/xujatasidolafox-xabuwufoje-kaxed.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • https://s3.amazonaws.com/dazemi/gusuluwedesuvexoladugikuj.pdfIn PDF document text
    • https://s3.amazonaws.com/firigugixujotov/major_north_american_rivers.pdfIn PDF document text
    • https://s3.amazonaws.com/vesubodufisi/android_version_7_phone_list.pdfIn PDF document text
    • https://s3.amazonaws.com/xixonu/70284250069.pdfIn PDF document text
    • https://s3.amazonaws.com/busutafitufe/how_to_relieve_gas_during_pregnancy_home_remedies.pdfIn PDF document text
    • https://s3.amazonaws.com/daxemo/ascii_character_codes_table_cheat_sheet.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e1c4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE1C4 4252 bytes
SHA-256: fb43bf9924f94ed575b1c0e79890a4a12ea0457612890af2a81d5dbea0c682cf
font_01_sfnt_off0000f0b4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF0B4 5084 bytes
SHA-256: 5c1dcca3fdb64aa485c485ade9724f21d1891af571928e7ab7afb20178ed4016
font_02_sfnt_off00010201.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10201 4680 bytes
SHA-256: c9b7ddea390693f2db01f37a4113936a57c4e7b29db1a518b115654eeb57fe25
font_03_sfnt_off000110dd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x110DD 11288 bytes
SHA-256: 1301329e6fb8607b1acaa087455fc8ca2c0c7a3f1b04d93bd5d17cc92355ce2c
font_04_sfnt_off00013708.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13708 16204 bytes
SHA-256: e93acd332f5893643511f4cefd38969ad5c744ad1b08842a788b6be7d277dd15