Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff3eb1e72e5b26a3…

MALICIOUS

PDF

74.3 KB Created: 2021-03-30 14:19:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 15ad3782ab190b5cbb52b098cf189a4c SHA-1: 44df7c607498d35141798af1e1512fd26580802b SHA-256: ff3eb1e72e5b26a33c3667a43218db1f02c07019a97108d9716059fc7272a15d
164 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains embedded JavaScript and a large number of external links, many of which point to suspicious domains. The ClamAV detection and ML classifier strongly indicate malicious intent, likely to exploit vulnerabilities or deliver a second-stage payload. The document body, though heavily obfuscated, contains references to 'wkhtmltopdf' and a date, suggesting it might be a generated document used as a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/award?keyword=clinical+chemistry+bishop+5th+edition+pdf
    • http://tvoeobrazovanie.fun/798268031124uz6w.pdf
    • http://tomogorman.com/why_is_my_karcher_pressure_washer_leaking_oilmwnnz.pdf
    • http://topcreditcheck.info/lawerobefuwegufifokozigak7dvrm.pdf
    • http://thecet.xyz/soundbot_sb571_portable_wireless_bluetooth_speakercy7x1.pdf
    • https://pubabugolutaj.weebly.com/uploads/1/3/2/6/132680974/142375.pdf
    • http://d-youtube.com/kadanulefepobalelogfl8ff.pdf
    • https://vexuzunudupugez.weebly.com/uploads/1/3/0/7/130740013/pegewetirufebelupolo.pdf
    • http://josamaduxano.22web.org/33614361540.pdf
    • http://tigutiput.iblogger.org/belkin_n300_wifi_range_extender_instructions.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/tunenijexe/alkene_alkyne_reactions_worksheet.pdf
    • https://9a86171b-24d8-4f43-8717-687e75280c8f.filesusr.com/ugd/6234e8_d20071433de0432caa0fda7f1aa1c75a.pdf?index=true
    • https://s3.amazonaws.com/meludav/69705309262.pdf
    • https://s3.amazonaws.com/xilasisefi/minecraft_cracked_servers_1._8_free.pdf
    • https://s3.amazonaws.com/risalenefazozo/boxclever_press_life_book_diary_2021.pdf
    • https://s3.amazonaws.com/meludav/34087421086.pdf
    • https://s3.amazonaws.com/kisimujuk/44506450242.pdf
    • http://totofexux.epizy.com/18866277405.pdf
    • https://s3.amazonaws.com/bomupi/boyong_manalac_movie.pdf
    • https://s3.amazonaws.com/fapaga/merawoluxopoxerivisosabij.pdf
    • https://ba739632-11db-41f7-a023-683a20e55d36.filesusr.com/ugd/99835b_a72206e66364402eae4b58cfade5ecb7.pdf?index=true
    • https://s3.amazonaws.com/jujojomojemiz/biohazard_4_pc_trainer_free.pdf
    • https://d1ee23ee-9ccf-45b0-80ef-1e1ff1f657c4.filesusr.com/ugd/9ef0c3_c78cbacf82cb436b8207b32b420e5e67.pdf?index=true
    • https://6b137298-3864-41c5-aaa3-11744000c3c2.filesusr.com/ugd/b916f4_bfd2c5b0b1624be88cd6404679cab64b.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e379.bin
6bae19f11088f1c1573811beb35d5a2b7999f1739eb83e989f1116d13ca75a2d
pdf-font-stream PDF embedded font (sfnt) at offset 0xE379 5668 bytes
font_01_sfnt_off0000f698.bin
9c58abcab9419d40c4b26fa8c481cd987fad4876e5f5d5256d28123e2dfe8739
pdf-font-stream PDF embedded font (sfnt) at offset 0xF698 10804 bytes