Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc37c6262f572cd4…

MALICIOUS

PDF

71.5 KB Created: 2021-03-25 12:13:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1eb27d7b46a82f255a84726f87c6ed02 SHA-1: d68aa203c7dab9054853445177fb9cf42864e61e SHA-256: fc37c6262f572cd497fc4ae85a22e422ca1189618687cca36c17946f81b95425
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document exhibits characteristics of a phishing or SEO spam campaign, as indicated by the PDF_SEO_LINK_FARM heuristic and the presence of numerous external URLs. The ML classifier and ClamAV detection strongly suggest malicious intent, likely to redirect users to malicious or phishing sites. No scripts were extracted, but the document's structure and embedded links point towards a tactic of overwhelming the user with external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=minty+pickaxe+generator+fortnite
    • http://masito.space/85882582973f24m7.pdf
    • https://donelodef.weebly.com/uploads/1/3/5/4/135401433/5541125.pdf
    • http://opensol.xyz/58804795284xky5a.pdf
    • https://dozetiwe.weebly.com/uploads/1/3/1/8/131856451/d0783e06bb295.pdf
    • http://agentsecure.space/62346132271zpsks.pdf
    • https://pabarubuvu.weebly.com/uploads/1/3/1/3/131379718/ce2eada9c08ebc.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://bf808793-8b46-4c54-8b11-319763181fa0.filesusr.com/ugd/0d018b_7a90a776967e4784aabe744483a2e137.pdf?index=true
    • https://s3.amazonaws.com/resabomibogodaw/epa_label_review_manual_chapter_7.pdf
    • https://uploads.strikinglycdn.com/files/be5a662b-1c9f-4400-93a4-9b43bf30e8da/25627008341.pdf
    • https://uploads.strikinglycdn.com/files/e294000a-2326-4df8-b972-c6900df50c53/47032152022.pdf
    • https://s3.amazonaws.com/sukedil/74965964152.pdf
    • https://s3.amazonaws.com/kovozenamofox/bed_sheet_manufacturer_near_me.pdf
    • https://s3.amazonaws.com/tinezedu/73534336527.pdf
    • https://s3.amazonaws.com/voxipanovigepiv/47045152575.pdf
    • https://s3.amazonaws.com/gorajikunobixi/da_aeriforme_a_solido_esempio.pdf
    • https://68e1e3d4-268d-49bc-a8aa-b119cb10fea7.filesusr.com/ugd/3ceeb9_108fb1a8ade34265be8b6012adebab08.pdf?index=true
    • https://uploads.strikinglycdn.com/files/8e5897ed-0763-4343-9819-b4a807cd63f5/61140035137.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000db14.bin
c7d6dc123a9688055143c436ba31b5feab2c32e9945979a822d665eef99737f0
pdf-font-stream PDF embedded font (sfnt) at offset 0xDB14 5212 bytes
font_01_sfnt_off0000ed07.bin
a2812cf557818b3df8fc0b77f34141d7e8741848cd39da0d58a03163a7584153
pdf-font-stream PDF embedded font (sfnt) at offset 0xED07 10332 bytes