Malicious PDF — malware analysis report

Static analysis result for SHA-256 1b205b4914e54c86…

MALICIOUS

PDF

87.1 KB Created: 2021-04-02 04:50:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-13
MD5: 487ffb37a35fd98441fe42f2ca80cc5a SHA-1: c9679c4b6750d69d814ad17b7a3d99c23f212431 SHA-256: 1b205b4914e54c867b9e7ef6c01e4d43424b013c91c8a2afb0abc9a410fb8522
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It functions as a link farm, containing numerous external URLs, with one prominent URL being `https://nipisod.ru/wix?keyword=1-5+exercises+geometry+answers`. The presence of many links on disposable hosting suggests an attempt at SEO manipulation or distribution of further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9955

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=1-5+exercises+geometry+answers PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4370269/normal_60565ddb047c5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391634/normal_5fd2c8a1d00e0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4467581/normal_603e15df1d14f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420934/normal_60328ef99c819.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://1f53f175-067f-4140-b001-f66bebc9855b.filesusr.com/ugd/c711d8_7b144c08b06f431e97ae1b838d031614.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/a38fafb4-3ccf-44ff-9218-6a5ea92afba1/35849331281.pdfIn PDF document text
    • https://6c8027e1-9878-41b3-a9ef-32ba2b6bcd02.filesusr.com/ugd/185811_a4e6fda20dcc491badced8792174a160.pdf?index=trueIn PDF document text
    • https://ba10d46a-d7c1-43af-8542-f1a50f31aa8a.filesusr.com/ugd/4dded2_c5397a5826e349f38eab3b15f442a778.pdf?index=trueIn PDF document text
    • https://c216880a-03a2-4774-ab7e-121c93799e8f.filesusr.com/ugd/b5aed9_37728d8a77c545cb983683be7bbe4fe8.pdf?index=trueIn PDF document text
    • https://38aad9b5-7a72-45b8-ac81-9fe73ce82000.filesusr.com/ugd/08338c_f4fb77b555a94f9489ed5d694c7d9a7f.pdf?index=trueIn PDF document text
    • https://78ff948a-0765-49f5-a22c-0fbe0eba7848.filesusr.com/ugd/888d0b_6a31cb39d19443228f1adffda9d6599c.pdf?index=trueIn PDF document text
    • https://5e9c932d-19a8-4d5a-a970-d4bc0bcb832b.filesusr.com/ugd/bae0a0_a92b70b5071a4cc5affb014d963312af.pdf?index=trueIn PDF document text
    • https://da18e6a8-d720-42de-a88c-3f13daad7efb.filesusr.com/ugd/08fe48_4c77475a138648028ad5b832ead702f6.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/tezude/pimeximiku.pdfIn PDF document text
    • https://af18ad75-7652-4b25-b9e0-8da5fded0af1.filesusr.com/ugd/529385_838c0122ec8544d5a3d58aecdab7f500.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/tobobowu/19843103850.pdfIn PDF document text
    • https://s3.amazonaws.com/pobixedele/58845671595.pdfIn PDF document text
    • https://1eba3b37-3dce-45e8-aa15-e51a58efc0fe.filesusr.com/ugd/89e37c_eaa8a4b6f3d54276b2af062c00b279c7.pdf?index=trueIn PDF document text
    • https://af8e4364-7f8a-45ec-af3e-d69da1c27fbb.filesusr.com/ugd/12c36c_52251d5c974d4299a5d16f853b53ac19.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/f8fb91b3-5cf5-4d2e-bb5a-3d352bac515e/mamavasan.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b1a359cb-e138-4d19-ab31-c825540090c3/67812270296.pdfIn PDF document text
    • https://a5a7f18c-b887-48a0-80cc-3627c14345d5.filesusr.com/ugd/609f59_9fbc8bbb4d0a430faa7ee6c64bacbdb2.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/juvuraguvutoxif/anbe_sivam_movie_song_starmusiq.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5d8f09e7-a8b8-4194-8f68-d8dbe6fdf131/dd_3.5_extra_classes.pdfIn PDF document text
    • https://6b238923-235f-4dbf-89f5-802ba9b9402e.filesusr.com/ugd/b914b5_38d39003d3c644d689473904be897db3.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/ropuba/64065427810.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fce3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFCE3 5460 bytes
SHA-256: 3f596214e38efa4908be96a2aa577742d1f0d536c6b8cbf914039df42407ac5a
font_01_sfnt_off00010f8a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10F8A 12080 bytes
SHA-256: 2ef4239e11c831482a25a6f6fc364e179f5cf787e1929854c788ebf46f6d0547
font_02_sfnt_off000138c3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x138C3 16300 bytes
SHA-256: ab0f8e6691f5ad8d5ab6d5f14fbec3a824af13cf7779946f1f4f3a149f3a72d0