Malicious PDF — malware analysis report

Static analysis result for SHA-256 fad6bd40d302be6a…

MALICIOUS

PDF

78.1 KB Created: 2021-03-31 10:29:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0501d359ee6726d77dd377ee885276e1 SHA-1: 7ddedd016436602d18e4e19f0045b4ea13701638 SHA-256: fad6bd40d302be6ae3d21bacc2ec1f74caa7ed28b92b9e7c6b8df6c34dd4738e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, identified as a PDF link farm, which is a common tactic for SEO manipulation and distributing malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution via the linked URLs. Although no scripts were explicitly extracted, the PDF structure and extensive URL list suggest it's designed to redirect users to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9964

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=ugly+duckling+book+characters
    • https://tawigijonepoter.weebly.com/uploads/1/3/4/0/134012415/c3e909bb25c.pdf
    • https://gewujezugiwo.weebly.com/uploads/1/3/4/7/134754524/8895489.pdf
    • https://static.s123-cdn-static.com/uploads/4388169/normal_60040c0797784.pdf
    • https://cdn.sqhk.co/powedaguja/gyBGBxh/deals_for_wish_discounts_free_shipping.pdf
    • https://cdn-cms.f-static.net/uploads/4470380/normal_602f20463182c.pdf
    • https://tololomajaju.weebly.com/uploads/1/3/4/4/134472688/felurem.pdf
    • https://wetejitaxazis.weebly.com/uploads/1/3/4/3/134306742/9876865.pdf
    • https://cdn-cms.f-static.net/uploads/4419413/normal_6058a402762f5.pdf
    • https://kenafowipadile.weebly.com/uploads/1/3/1/4/131437871/wudajujutosine.pdf
    • https://cdn.sqhk.co/piwoputi/tgiHgd5/birthday_wishes_song_in_marathi.pdf
    • https://rapagifetudi.weebly.com/uploads/1/3/2/6/132682686/mobuvedorak-fefejoxagunet.pdf
    • https://cdn.sqhk.co/riwaxagi/chgigqL/carnival_cruise_lines_reopen.pdf
    • https://fanakigefepawaf.weebly.com/uploads/1/3/0/8/130873796/1893c6c541978eb.pdf
    • https://cdn-cms.f-static.net/uploads/4417208/normal_6011a955989d6.pdf
    • https://cdn.sqhk.co/lakanodip/EBQPhem/what_disney_animal_are_you_quiz_playbuzz.pdf
    • https://cdn.sqhk.co/letarezetap/jjgcjiX/bluestacks_hd_app_player.pdf
    • https://cdn.sqhk.co/zefipuvuwifi/Q4IQ0ig/53046473713.pdf
    • https://cdn.sqhk.co/wemorapi/jhiiEVR/tip_calculator_for_pizza_delivery.pdf
    • https://cdn.sqhk.co/danuzenanini/76dgjkw/88007548741.pdf
    • https://letobepep.weebly.com/uploads/1/3/0/7/130740206/tepuwepesisowimavez.pdf
    • https://fubalaxusagipun.weebly.com/uploads/1/3/4/1/134108832/fa5c3a880ed7fe.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/tumuzu/sarcomere_coloring_biology_corner_answers.pdf
    • https://s3.amazonaws.com/rubidokezive/4k_wallpaper_for_iphone_x.pdf
    • https://s3.amazonaws.com/ruzaganog/9631562781.pdf
    • https://s3.amazonaws.com/bokofapig/best_english_teaching_methods.pdf
    • https://s3.amazonaws.com/muwemivumazulax/how_to_use_nested_classes_python.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f41c.bin
226a40b90f9d84109df40af7ae73247d1318dbbb9be3b9263a108522bfca74db
pdf-font-stream PDF embedded font (sfnt) at offset 0xF41C 5496 bytes
font_01_sfnt_off000106cf.bin
877afb0f3dd83d7fa1ef856af7b109ec58dd930527d300f7f89dbac354b9d5e0
pdf-font-stream PDF embedded font (sfnt) at offset 0x106CF 10868 bytes