Malicious PDF — malware analysis report

Static analysis result for SHA-256 1eb233212d7f3060…

MALICIOUS

PDF

75.1 KB Created: 2021-03-28 16:43:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 70b3101795e1ec37af4afbf8cffd32ae SHA-1: e47a184ed27f634225de87e5c4c132aacb74c03f SHA-256: 1eb233212d7f3060544862f4ac35987c8cad18db67655b4fa730f96a9d359def
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, many of which point to other PDF files, indicating a link farm designed to attract search engine traffic. The 'School magazine layout pdf' text suggests a lure to trick users into downloading these linked PDFs, which are likely malicious based on ClamAV detection and ML classification. The presence of numerous unknown reputation URLs further supports the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/award?keyword=school+magazine+layout+pdf
    • http://megahit.space/pearson_psychology_chapter_8_quiz_answerso46rx.pdf
    • https://xizulorojude.weebly.com/uploads/1/3/5/3/135391297/9239987.pdf
    • http://vashe-zdorovie.xyz/585562704006d3qj.pdf
    • http://1xbet-regi.site/microsoft_authenticator_desktopm33dd.pdf
    • https://xogovowumo.weebly.com/uploads/1/3/0/7/130738979/9266981.pdf
    • http://datinge.site/92390678737aqhtw.pdf
    • http://phillipen.online/feminist_film_theory_explainedx3awb.pdf
    • http://kersita.fun/xifagelekatunenevir7f3.pdf
    • https://nodopotol.weebly.com/uploads/1/3/4/0/134018708/7902373.pdf
    • http://kellys.space/introduction_to_financial_accounting_11th_edition_answersl1ncq.pdf
    • https://rojanebe.weebly.com/uploads/1/3/1/6/131637229/dozarurop.pdf
    • http://creamwalls.space/oxford_modern_english_grammarh0z1e.pdf
    • http://biomanix.best/777613546549n012.pdf
    • http://vzruvayarttraff.xyz/my_samsung_refrigerator_ice_maker_isnt_workingdoupq.pdf
    • http://gratoraama.space/69207067500o3dvw.pdf
    • https://panejukirid.weebly.com/uploads/1/3/1/6/131606092/loninuwafo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://ridezaxepaked.rf.gd/11928011017.pdf
    • https://6998e30b-c911-4113-ab34-4c15204891c7.filesusr.com/ugd/429b25_04ae689a05e545ae81784be120e14567.pdf?index=true
    • https://ba3a7bb5-edd2-4228-b29c-cf272df6a868.filesusr.com/ugd/bd1c09_043c76e5e5aa47efb56dca55c3906713.pdf?index=true
    • https://065b66ee-25d8-4381-b309-094abc4d823c.filesusr.com/ugd/2703e6_0af9adbe078e4ef99064be0da67206bd.pdf?index=true
    • http://bijamujijupife.epizy.com/zekorutifatiman.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e7da.bin
c6d0814ed94e5115b3a4e7799c0eb3e0706f4c4ad44ba45232285d408baec000
pdf-font-stream PDF embedded font (sfnt) at offset 0xE7DA 5548 bytes
font_01_sfnt_off0000faac.bin
1165f9e7110a74b0ba2e21133bc0780df3b0c968cdcc4fc9c120ff02057c66f4
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAAC 10792 bytes