Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7fc316349ed6e79…

MALICIOUS

PDF

100.7 KB Created: 2021-03-23 09:58:01 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 43e2f079a4e24a81035f88e58f803a24 SHA-1: d914750d29c249a4553bfa221c7064f7931d15cf SHA-256: f7fc316349ed6e79664111e5f3877447aeea3450001214663b17171e7c729269
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many of which are part of a link farm designed to manipulate search engine results. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for SEO spam or phishing. While no scripts were explicitly extracted, the PDF structure and embedded URIs suggest it's designed to redirect users to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/wix?keyword=minecraft+military+base+seed
    • https://bedejoxinen.weebly.com/uploads/1/3/1/1/131163540/efe6381110678.pdf
    • https://cdn.sqhk.co/zupololano/aijifja/sun_tzu_history_channel.pdf
    • https://vewenikeluw.weebly.com/uploads/1/3/0/7/130739128/puzolada.pdf
    • https://kupowenip.weebly.com/uploads/1/3/4/0/134042521/fda63ce435.pdf
    • https://cdn.sqhk.co/sabimejuka/IBjdOoM/macroglobulinemia_waldenstrom_guidelines.pdf
    • http://sodahub.pro/55126338642dk7qg.pdf
    • http://tophomework.space/46603071045u5x1y.pdf
    • http://savineme.mywebcommunity.org/sikagolupebokuzanunileru.pdf
    • https://cdn.sqhk.co/naxupowu/ietRhhW/dujaroxamexupum.pdf
    • http://govnosiakxws.online/ck-12_geometry_answer_keyvhizj.pdf
    • http://leporabev.mywebcommunity.org/what_is_10_wt_hydraulic_oil.pdf
    • http://vosajizegek.mypressonline.com/daxenabunaduwibejet.pdf
    • https://cdn.sqhk.co/lafuwexale/bhdwPbs/mobile_ringtone_2020_music.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/likerajatob/77483389216.pdf
    • https://s3.amazonaws.com/tanikanaw/88175599815.pdf
    • https://uploads.strikinglycdn.com/files/4c5d6ec8-d59d-49a0-92b5-1bccf2f47ed7/how_bad_can_i_be_spanish_lyrics.pdf
    • https://s3.amazonaws.com/borokegujuzero/rascals_movie_bluray.pdf
    • https://uploads.strikinglycdn.com/files/d7a0bbd2-9b98-4d58-ac7d-df51f67f3b1c/66460596475.pdf
    • https://s3.amazonaws.com/tobovunoberiki/63809868589.pdf
    • https://s3.amazonaws.com/vuxalirudidel/geometric_series_worksheet_answers.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00014d5d.bin
ab6d99563d0926403ec6c27a7f752fac295be97a9a348e6e249c204539c652a2
pdf-font-stream PDF embedded font (sfnt) at offset 0x14D5D 5416 bytes
font_01_sfnt_off00015fc4.bin
647342e1dbbbc8785fdea712129cc41460d751a5769838ee162d72586dee4482
pdf-font-stream PDF embedded font (sfnt) at offset 0x15FC4 10916 bytes