Malicious PDF — malware analysis report

Static analysis result for SHA-256 08dae92f5ae80a7d…

MALICIOUS

PDF

98.1 KB Created: 2021-05-18 22:56:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-25
MD5: eb196b90ec4b35faa3f804e06cdfc69e SHA-1: bc518a951b156d6ba28d8dac38b8471b11c5f9d3 SHA-256: 08dae92f5ae80a7d47b4434006f1db6570278458fd55d0c0d7919245f417ed74
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which point to a redirector URL designed to host SEO-optimized content. The primary URL, https://nipisod.ru/strik?utm_term=harry+potter+deathly+hallows+part+2+script+pdf, suggests a lure for a movie script PDF. The presence of a PDF link farm and a high ML classifier score indicate malicious intent, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=harry+potter+deathly+hallows+part+2+script+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4471230/normal_6066815a52bf4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4490739/normal_600cf51047ea3.pdfIn PDF document text
    • https://lavozeto.weebly.com/uploads/1/3/0/7/130775819/0a208.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4382627/normal_5fc795e3b2ff4.pdfIn PDF document text
    • https://pudewufaziv.weebly.com/uploads/1/3/0/7/130739775/5c452d5879484.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4461773/normal_5fdf55376b03d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370064/normal_605f584862852.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4456369/normal_6046e9081d3ac.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4414335/normal_603436c84e3c4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4460461/normal_6034383ad78ba.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/164e8e7a-ed0b-4748-a740-0452a92f89bd/98715855826.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/78f5a6ac-4f80-468a-82ee-bf11d5c3115e/basic_physics_equations.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f579d8ad-0991-40a2-83e7-b66f883d13cf/sepasovemetolomokosar.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9a11f57e-d531-45bc-98e3-772c08b8a2c9/20017551683.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b87145a9-fd88-45b5-a163-310a56dbdb43/nerozovobanev.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b76137d4-2c90-4cb5-899c-776b64d26e74/27309166862.pdfIn PDF document text
    • http://novegiw.rf.gd/automation_framework_development_with_selenium_c.pdfIn PDF document text
    • http://gozefanilufi.epizy.com/hotel_revenue_management_books.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa41c215-32d4-467e-bb4c-a6dda515ff5a/bhagavad_gita_telugu_online_reading.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/648c12f2-acbc-4061-816c-adec090e4953/nasb_macarthur_study_bible.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012e89.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12E89 5532 bytes
SHA-256: fab2511109eec5fc29f18c848d1ae4812f712b0a3c4e54bfbcf236de14bbf780
font_01_sfnt_off00014170.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14170 10352 bytes
SHA-256: 4dcd705de78a931efdab163c8beef36373d7c278b796f6fe261c026fa8ca29a3
font_02_sfnt_off000164cd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x164CD 16204 bytes
SHA-256: 532315dfdc59b350d447ad91845dd8cc72a836e684f536ab9a4305dc5b53fb8e