Malicious PDF — malware analysis report

Static analysis result for SHA-256 f561d57e8ec375af…

MALICIOUS

PDF

110.1 KB Created: 2020-12-20 00:18:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 525235b853b7f5b2413c301fe30e53f4 SHA-1: 12c8e8f0cf7e7cf47eeac1d0d65e6faceaec13c4 SHA-256: f561d57e8ec375afa3050233b704a68b00fde6e5715da6c721e2bb2faf66eccf
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of embedded links, with the primary link pointing to a known malicious redirector. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external PDF links, suggesting an attempt to manipulate search engine results or distribute further malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/123?utm_term=vishnu+sahasranamam+english+prapatti
    • https://static.s123-cdn-static.com/uploads/4421050/normal_5fc9ada5af802.pdf
    • https://bejitukinerebi.weebly.com/uploads/1/3/4/8/134890105/18c9754.pdf
    • https://rigivopamakor.weebly.com/uploads/1/3/4/8/134869382/mewuxades.pdf
    • https://fuxiwajusefu.weebly.com/uploads/1/3/4/6/134617271/c0402.pdf
    • https://static.s123-cdn-static.com/uploads/4458150/normal_5fcaad450fea8.pdf
    • https://rawixokuboja.weebly.com/uploads/1/3/4/0/134097397/jotili-wisunujika-digegebe-bubanukulete.pdf
    • https://fesinukovib.weebly.com/uploads/1/3/4/7/134715349/worerebekulakopoke.pdf
    • https://sewobefavewekog.weebly.com/uploads/1/3/4/3/134367647/4984895.pdf
    • https://jevikefogonilij.weebly.com/uploads/1/3/4/7/134747067/mipevumudiba.pdf
    • http://fedorahosted.org/lohit
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102Hussain
    • http://smc.org.inhttp://smc.org.in
    • https://s3.amazonaws.com/tutasujal/logo_dls_persija_2019.pdf
    • https://s3.amazonaws.com/ritoma/mudiser.pdf
    • https://s3.amazonaws.com/zukogi/36985495918.pdf
    • https://s3.amazonaws.com/wifukedot/kickstarter_campaign_guide.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • https://gitlab.com/smc/meera/blob/master/COPYING

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0001275c.bin
ac4c17ea7856462909ebbe9fc7030d79fe8e2953ee2477d9cb0c435b015cbfba
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1275C 13836 bytes
font_00_sfnt_off0000c8c5.bin
816d4b2cbf3d6ca89fdc6b4ae54b4348fdb17946965ee372507d7921631024ab
pdf-font-stream PDF embedded font (sfnt) at offset 0xC8C5 5200 bytes
font_01_sfnt_off0000da48.bin
b175586dc0d37c80b7e846660fe88fd24ee8159186d32edb9c29714458915f92
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA48 10120 bytes
font_02_sfnt_off0000f52c.bin
4eab9380b8cace64d3e98e70f953563aca6ee0e67d4a9d380bc10de5513652cf
pdf-font-stream PDF embedded font (sfnt) at offset 0xF52C 9256 bytes
font_03_sfnt_off00011307.bin
16bd8e35688e351001769e39990d52fb0f5c28f31434f33c243eafa348dd2ccd
pdf-font-stream PDF embedded font (sfnt) at offset 0x11307 5544 bytes
font_05_sfnt_off00014800.bin
85d80dd345d5015e7e908e645bd95fa262511b8ab87dc5bd0c49d61b04894243
pdf-font-stream PDF embedded font (sfnt) at offset 0x14800 15140 bytes
font_06_sfnt_off00016d53.bin
ff816ee37e22f963fb529b2cce11d8014e16f2cc04d6643321f31413ddb13927
pdf-font-stream PDF embedded font (sfnt) at offset 0x16D53 11288 bytes
font_07_sfnt_off0001916e.bin
541231773bc34839d43b53d3ed822cb1b49b67b8e50707414f7ac1d5d8f0eca6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1916E 6916 bytes