Malicious PDF — malware analysis report

Static analysis result for SHA-256 f74824f3a5652414…

MALICIOUS

PDF

86.3 KB Created: 2021-02-19 11:40:04 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c0b985601e90db333ce85a41776305d4 SHA-1: b77ad7284e085f20f2a2faeb9f4ab9d195a3e509 SHA-256: f74824f3a5652414b4afebdec05bcbbf9901e36568201ebc750892426c167c11
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and ML classifiers, exhibiting characteristics of a phishing or SEO poisoning attack. It contains a large number of external links, many pointing to PDF files, suggesting a link farm designed to manipulate search engine rankings or redirect users to malicious content. The embedded URLs and the overall structure strongly indicate an attempt to drive traffic to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=ffxiv+ravana+ex+guide
    • http://ukranews.site/24896427559wq9q3.pdf
    • https://cdn.sqhk.co/ragojagef/JrGiehd/61135642561.pdf
    • https://static.s123-cdn-static.com/uploads/4380073/normal_5ff9d2a803f3f.pdf
    • http://thecaffeinatedstudent.com/the_sociology_of_health_and_illness_critical_perspectivesa5swe.pdf
    • http://masterpowerpoint.com/38898577503av1no.pdf
    • https://nopolojeg.weebly.com/uploads/1/3/5/3/135349815/zopetotex.pdf
    • https://kefawefixak.weebly.com/uploads/1/3/0/7/130738991/gezawulawesagi.pdf
    • http://afracheat8.xyz/rirapiborawivibeto4tnk1.pdf
    • https://vubeluzuge.weebly.com/uploads/1/3/4/3/134357782/sawun_tofusadozewu_witedil.pdf
    • https://lawagupavuraxap.weebly.com/uploads/1/3/4/6/134616311/gawawutijedevutulaga.pdf
    • http://therarbooks.com/99611494292zvx1a.pdf
    • https://mikugixu.weebly.com/uploads/1/3/1/4/131438693/1488570.pdf
    • https://cdn.sqhk.co/nofatazor/ifhdxha/piborurutenuxedopago.pdf
    • https://cdn-cms.f-static.net/uploads/4411932/normal_5fda508da2c37.pdf
    • https://legovizadedugid.weebly.com/uploads/1/3/1/8/131856283/dirowi-minajuve-supalowarig.pdf
    • http://custits.space/nursery_rhymes_video_songsq9s1m.pdf
    • http://love-cosmetics.shop/euchre_score_sheet_templatea3fpf.pdf
    • http://glasshookahcatering.com/rajasthan_commercial_tax_c_form_verificationqgj57.pdf
    • https://fukoroxovelamos.weebly.com/uploads/1/3/0/7/130776486/femeparipim.pdf
    • https://cdn-cms.f-static.net/uploads/4407988/normal_602b391d1e3bc.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eef6.bin
ea7673db091e6e8289e9691dbd1993d40cca8eeabcdcf2b2915a402f6f9a1cb6
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEF6 4640 bytes
font_01_sfnt_off0000fec6.bin
2e6b92ac6266733abf47250a677a58f1cb9058eadb9ca88465c27119526d4603
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEC6 13048 bytes
font_02_sfnt_off0001289d.bin
9af6fc3bf9d751f70540aea0fa47faa159a3604992cda23d2adcda3ffc5346b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1289D 16092 bytes
font_03_sfnt_off00013d64.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x13D64 4324 bytes