Malicious PDF — malware analysis report

Static analysis result for SHA-256 f4bb8ba07219519f…

MALICIOUS

PDF

87.7 KB Created: 2021-03-23 07:48:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dc0771d75947abf48c267af8a9b441a4 SHA-1: 24d27e4b6c1873cbe1986486adfcbd64a1cd3fd8 SHA-256: f4bb8ba07219519fa80786cddbdf246e96f01343eb456152fe7130bb7fb1d520
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a mass external link farm, with numerous URLs pointing to other PDF documents, indicating a SEO spam or link-farming operation. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and URL patterns are consistent with malicious document delivery mechanisms.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=what+are+the+curriculum+design+models
    • https://gamidamivagug.weebly.com/uploads/1/3/5/3/135324690/lomofefini.pdf
    • http://joxutikomujawi.iblogger.org/joluzosexikilori.pdf
    • https://gidaletibom.weebly.com/uploads/1/3/4/8/134881461/kuwisuzike.pdf
    • https://vagobodowi.weebly.com/uploads/1/3/4/6/134600101/ganebesorezo-rexezufaxikon.pdf
    • https://lifalaril.weebly.com/uploads/1/3/4/8/134883644/3637211.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/51a837c1-8319-4095-bbf4-2d123b6bd657/is_it_possible_to_learn_python_in_a_week.pdf
    • http://jutagejefutix.atwebpages.com/93909953843.pdf
    • https://19a39513-20cc-49d1-a75c-e30ce0314142.filesusr.com/ugd/f99735_5eaaaa5aac2c4936a4c5241d68c635f3.pdf?index=true
    • https://uploads.strikinglycdn.com/files/37948ed4-9c87-48c7-bf4c-4fa9f683f3a8/wolf_oven_self_clean_time.pdf
    • https://uploads.strikinglycdn.com/files/a2e7b17d-8b81-4237-bc86-f685d0cef012/psychology_textbook_high_school.pdf
    • http://xakosafejel.epizy.com/zokedoweneva.pdf
    • https://uploads.strikinglycdn.com/files/53574131-ca35-426b-8c60-3cceb95ea498/what_to_eat_for_a_flat_belly.pdf
    • https://c3373aeb-ed74-4f2d-b631-fa679e0a3f6f.filesusr.com/ugd/cbe7f7_577137c5679e424e99957e5fd0929ab4.pdf?index=true
    • http://lelikerakovet.atwebpages.com/pancreas_anatomy.pdf
    • https://uploads.strikinglycdn.com/files/3cfde823-1059-4524-8447-1c2682edc6f3/will_stocks_continue_to_rise.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000118d5.bin
c57042fd111f1166da54477469e6491540c738d65fb82a2d17b388382bfe9d90
pdf-font-stream PDF embedded font (sfnt) at offset 0x118D5 5364 bytes
font_01_sfnt_off00012af2.bin
c9b5c8424ffab192b439aadabbb46d602f547c1f3e701a74ed6a3215ad621690
pdf-font-stream PDF embedded font (sfnt) at offset 0x12AF2 10844 bytes