Malicious PDF — malware analysis report

Static analysis result for SHA-256 fca8b05d80e659d9…

MALICIOUS

PDF

76.2 KB Created: 2021-03-17 04:56:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-02
MD5: ff1277a23bb7a72c139335aab5daf39f SHA-1: 98f97a182351899e1b1b480b2bf480664c2b8ca4 SHA-256: fca8b05d80e659d9fd040adccf1abb195fb2e67b376f1d87a1a516666c37b93b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are SEO-optimized and point to benign content, suggesting a link farm or SEO manipulation tactic. One critical heuristic identified a mass external PDF link farm. The embedded URL points to a suspicious domain, likely intended to host malicious content or phishing pages. No scripts were extracted, but the PDF structure and heuristics indicate a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/award?keyword=real+estate+contract+addendum+pdf PDF link annotation
    • https://lewanodeb.weebly.com/uploads/1/3/4/8/134885095/toxodu.pdfIn PDF document text
    • https://dokebama.weebly.com/uploads/1/3/2/6/132681336/1868c63f.pdfIn PDF document text
    • https://cdn.sqhk.co/xejexeremiso/PghXphc/highest_scrap_copper_prices_near_me.pdfIn PDF document text
    • https://pixumoxijabana.weebly.com/uploads/1/3/4/7/134748481/zixuguto-kizamarisilip.pdfIn PDF document text
    • https://cdn.sqhk.co/jukusenefow/eWAjcjj/rowuteritufi.pdfIn PDF document text
    • https://cdn.sqhk.co/lanuniwa/h4GoChb/vactor_2100_operator_manual.pdfIn PDF document text
    • https://jajibesuwazigix.weebly.com/uploads/1/3/1/3/131383486/bodef.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/wetevali/rational_and_irrational_worksheet.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6d3f6f48-bf8c-4818-9bf0-b7db116cdc14/30716097809.pdfIn PDF document text
    • https://s3.amazonaws.com/bolovopizonuki/57536009102.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0d93cfdf-818f-455e-986d-bf053c01b5c8/libro_de_quimica_organica_descargar_gratis.pdfIn PDF document text
    • https://s3.amazonaws.com/dudigonifu/free_google_slides_templates_for_students.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ac5edc2b-8c46-4d80-9ea5-3449b447560f/60281902992.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3b63c126-0655-4e45-9be9-5b69cdaa9305/6387814750.pdfIn PDF document text
    • https://s3.amazonaws.com/dopugaxelelema/enlil_vertical_axis_wind_turbine.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9250eedf-8c25-4b79-b098-b8dd7d7f5b33/83411964079.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fc1d9417-30b9-43a6-ab6b-6cffd5ec1836/viwukuzazofobegob.pdfIn PDF document text
    • https://s3.amazonaws.com/jijari/angry_birds_movie_in_english_2016.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/769e0e08-7a53-4f04-aa6c-257b1ff562b8/best_scope_rings_for_marlin_336.pdfIn PDF document text
    • https://s3.amazonaws.com/fizaxo/uidai_aadhar_update_app.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ef0f3481-566a-434d-b7c3-359c72b6665c/islanders_flyers_game_1.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/da3718ec-fbeb-43ae-b0d3-81c6f8e60fe2/72874242206.pdfIn PDF document text
    • https://s3.amazonaws.com/luramamelolem/rejabetejesawijot.pdfIn PDF document text
    • https://s3.amazonaws.com/rebomedug/barcode_font_for_windows_10.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea13.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEA13 5308 bytes
SHA-256: a2adbb231683c10418e02693a106490bdcdda27ba35bd60ec5feb05e7dec4fea
font_01_sfnt_off0000fc10.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFC10 10956 bytes
SHA-256: 678a47c2783fb542e8f5953495ebb414c54f04346f050a2e57effe551640ab24