Malicious PDF — malware analysis report

Static analysis result for SHA-256 f691386fb1e8a237…

MALICIOUS

PDF

73.7 KB Created: 2021-02-16 03:44:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-12
MD5: 01c91a74bca31b2437059c1d731adeb1 SHA-1: 2c6d249a4046e92c857141d7c34a1dbd9881ffe7 SHA-256: f691386fb1e8a237b7d463e1e689bca5a7cac0370891ade82be94542aa4fd26b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to potentially malicious domains, indicative of a link farm or phishing attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were explicitly extracted, the presence of embedded URLs and the PDF structure itself suggests an attempt to redirect users to malicious content, likely for SEO manipulation or to host phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/strik?utm_term=un+curso+de+milagros+leccion+130 PDF link annotation
    • https://mosaminaworite.weebly.com/uploads/1/3/1/6/131636744/jipikipen.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4471960/normal_5feb9d3972be1.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4391624/normal_5ffe8ae1c8e9b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4495240/normal_5fd28393bc12e.pdfIn PDF document text
    • https://jabudebixeref.weebly.com/uploads/1/3/4/3/134398441/zujezaz_luwov_kulexulo_gajaguteniwo.pdfIn PDF document text
    • https://mirajaxudedina.weebly.com/uploads/1/3/0/7/130775596/7616366.pdfIn PDF document text
    • https://bapoxaluw.weebly.com/uploads/1/3/4/7/134717037/774232d.pdfIn PDF document text
    • https://welomutulek.weebly.com/uploads/1/3/4/8/134873792/beweponosonav.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/jenisozazewubo/bing_crosby_white_christmas_sheet_music_free.pdfIn PDF document text
    • https://s3.amazonaws.com/tixeligufokup/chevrolet_beat_2019_ficha_tecnica.pdfIn PDF document text
    • https://s3.amazonaws.com/mejigavukolu/fractions_worksheets_halves_and_quarters.pdfIn PDF document text
    • https://s3.amazonaws.com/ribowexulo/catia_v5_learning.pdfIn PDF document text
    • https://s3.amazonaws.com/solonebosop/renew_us_passport_for_minor_form.pdfIn PDF document text
    • https://s3.amazonaws.com/veraxawewib/traduction_anglais_franais_offline_apk.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d440.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD440 5408 bytes
SHA-256: 24db57a5c0f683a3bc4c3115331e05e082ca2d207441a50902755377506ef8aa
font_01_sfnt_off0000e679.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE679 11152 bytes
SHA-256: 79b7bf09fa70e3aaf92aa747c52ac745f6a90ab14e77688720872465479d60f4
font_02_sfnt_off00010a55.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A55 4324 bytes
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f