Malicious PDF — malware analysis report

Static analysis result for SHA-256 f946805ee9dc0459…

MALICIOUS

PDF

91.7 KB Created: 2021-05-28 15:45:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 775dc1c87c79a0ac5a3d166a36e15dac SHA-1: 6999cc85e55a42f7f4229068bbe0a8ce75405110 SHA-256: f946805ee9dc04596cc473507910896dfbd7ccf38fcb761685428e9e0774d6d8
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many of which are part of a link farm designed to direct users to potentially malicious sites. The ClamAV detection and ML classifier strongly indicate malicious intent, likely for phishing or distributing further malware. While no scripts were explicitly extracted, the PDF structure and embedded URIs suggest it's designed to exploit user curiosity or trust to redirect them to attacker-controlled infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9926

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=r+data+analysis+examples+pdf
    • https://lerogufoporix.weebly.com/uploads/1/3/4/8/134885840/080263a.pdf
    • https://zitakutuseg.weebly.com/uploads/1/3/5/9/135994262/ac05e62.pdf
    • https://wuwemupijebuvat.weebly.com/uploads/1/3/4/0/134012408/6601c5fd9c78.pdf
    • https://bupiwuzisulim.weebly.com/uploads/1/3/0/8/130874125/ad4a1e.pdf
    • https://jedopebo.weebly.com/uploads/1/3/4/8/134889916/6726201.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/5392104d-2297-4ab9-b157-71f8f50a5d0d/xidepupobawos.pdf
    • https://uploads.strikinglycdn.com/files/d2ee5598-4217-4aa5-897f-65ad12f78f34/funofajasofa.pdf
    • https://uploads.strikinglycdn.com/files/5095bc33-de8a-4c77-9dd6-9abc0db5a552/filupukumefesopujotemi.pdf
    • https://uploads.strikinglycdn.com/files/c1d6aa4f-47b1-4172-9e69-71c15c557761/best_way_to_self_study_for_ccna_routing_and_switching.pdf
    • https://uploads.strikinglycdn.com/files/751ab632-cdc0-48e9-82fd-48656a21104d/psilocybe_cubensis_grow_kit_reddit.pdf
    • https://uploads.strikinglycdn.com/files/c14d9064-f687-451b-a239-1f6c8780083b/12386370784.pdf
    • https://uploads.strikinglycdn.com/files/8b29599e-5403-495e-9b00-c1457458cc2d/pirorubogitirapukuxuzebi.pdf
    • https://uploads.strikinglycdn.com/files/c872ce11-8c74-42fa-b57b-df7124cd01c7/76980497510.pdf
    • https://uploads.strikinglycdn.com/files/b511a5c3-0431-4753-b916-d1498db3e28e/rumexuguruvebuwebanopufo.pdf
    • https://uploads.strikinglycdn.com/files/c0a8fc67-7c63-482d-914b-7b2ecfa0906c/rutosam.pdf
    • https://uploads.strikinglycdn.com/files/eb1a839f-9866-4a78-80c4-5ada1e545c71/bonding_cast_fred.pdf
    • https://uploads.strikinglycdn.com/files/02c565e0-54aa-4112-ac8c-0bf4d8230d16/zowifap.pdf
    • https://uploads.strikinglycdn.com/files/7565c629-537c-4b71-8105-f4f465271dbb/8897226235.pdf
    • https://uploads.strikinglycdn.com/files/2348fb13-c1fd-48a3-8671-e160ee76ddd7/3.idiots.2009.bluray.1080p_free_download.pdf
    • https://uploads.strikinglycdn.com/files/d86903bb-8b41-4b99-867d-8cffe7f5f7e3/93076495453.pdf
    • https://uploads.strikinglycdn.com/files/017e05a8-b360-4599-9dbc-c1914c582101/12682940288.pdf
    • https://uploads.strikinglycdn.com/files/8977c536-e17f-4f0b-8203-0e5bd001a2b8/csgo_aimbot_free_2019.pdf
    • https://uploads.strikinglycdn.com/files/dccd3ee1-5f9b-4b51-87e2-59fba66d3232/mutarazejijop.pdf
    • https://uploads.strikinglycdn.com/files/c800c992-81d5-411d-a0b0-7e5f47d388fa/tujokipilodufugofatanez.pdf
    • https://uploads.strikinglycdn.com/files/03a12bba-d11c-40f0-b29d-11cf38774d6b/24838068369.pdf
    • https://uploads.strikinglycdn.com/files/565a6f75-9fe6-4b38-842a-1f42b6924eed/libros_de_metodologia_dela_investigacion_cientifica_para_descargar_gratis.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001014f.bin
2db3e748bf8732130c1356ced66838a6216c69784c0f13f1bb56004f0cab3cbf
pdf-font-stream PDF embedded font (sfnt) at offset 0x1014F 4948 bytes
font_01_sfnt_off0001121c.bin
67f036d4ae6dd24274feaf95b48a0fc0c342f14e044f981cc7569632bb87ef79
pdf-font-stream PDF embedded font (sfnt) at offset 0x1121C 10804 bytes
font_02_sfnt_off00013753.bin
41f5c53eac48dabfa41a90d199c6dc0d57bd20af15813533c5a32caa26d6b256
pdf-font-stream PDF embedded font (sfnt) at offset 0x13753 18048 bytes
font_03_sfnt_off000152b3.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x152B3 4324 bytes