Malicious PDF — malware analysis report

Static analysis result for SHA-256 31535e17d51dbf75…

MALICIOUS

PDF

71.5 KB Created: 2021-03-05 00:05:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 2c46b9a6e33f274108e5fd9794b06947 SHA-1: df78c0f3c3c82839be4f7b8d764accfcdbf22ffa SHA-256: 31535e17d51dbf757c71eff9071925d6f88d288f7fa8097c5496197491db1456
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains a large number of external links, many hosted on disposable domains, suggesting a link farm or phishing operation. The document body, though heavily obfuscated, appears to reference book downloads, a common lure for users. No scripts were extracted, but the presence of numerous external URLs points to a potential drive-by download or redirection to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/123?utm_term=tides+of+darkness+book+pdf PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4392210/normal_5fe58dc5e7453.pdfIn PDF document text
    • https://nupetumagapet.weebly.com/uploads/1/3/1/8/131859993/jigavuxitafa.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4369324/normal_5fe278410e1b3.pdfIn PDF document text
    • https://wivutukezed.weebly.com/uploads/1/3/1/4/131438473/0c399c282377.pdfIn PDF document text
    • https://zekenegelu.weebly.com/uploads/1/3/4/3/134390475/f0e969b916422a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4373768/normal_601e834d9bc5c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4376372/normal_5fc7e61c50d8f.pdfIn PDF document text
    • https://jixejuterekafiw.weebly.com/uploads/1/3/4/5/134508928/5575540.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://6f12065f-c45d-410c-b048-6ec23fb2b810.filesusr.com/ugd/02ccf7_595b7a8a139c454aad8016350404c460.pdf?index=trueIn PDF document text
    • http://vupifokixen.rf.gd/refojoribezosezozonujufi.pdfIn PDF document text
    • http://xufizup.rf.gd/introduction_to_accounting_curtin_book.pdfIn PDF document text
    • https://69c5641f-197a-42c1-bef1-daa502c1f1d7.filesusr.com/ugd/948cea_2460666b5fd04b54a437238c1ece7e5e.pdf?index=trueIn PDF document text
    • https://33edd578-4186-4695-89f3-f56a5a23fc53.filesusr.com/ugd/f17c08_c6be9566fc464e5390006f1a48243c97.pdf?index=trueIn PDF document text
    • https://3ff4c494-4984-418a-b709-7a5c611cca0a.filesusr.com/ugd/adbee0_b8c8b7cdb1d8487a998b35dda67bd0bb.pdf?index=trueIn PDF document text
    • https://923a8ca3-316b-4844-b38f-9bc955ad4852.filesusr.com/ugd/312e0e_461367eb3d5e4fe79e4e911f50f1ab11.pdf?index=trueIn PDF document text
    • http://fukibas.epizy.com/m._sc_exam_date_sheet_2018.pdfIn PDF document text
    • https://ddf64d59-5240-4154-9987-17dfc28e22c7.filesusr.com/ugd/cec570_ef3ea21afb94471395489bca90499b1f.pdf?index=trueIn PDF document text
    • https://a39ac558-8fe8-437d-9e10-dc9402d6cb9c.filesusr.com/ugd/1ebe14_0eb2259700fb4c51af481ede32494b9f.pdf?index=trueIn PDF document text
    • http://siwupogogu.rf.gd/best_billboard_songs_2018.pdfIn PDF document text
    • https://5e0c4d4d-41f9-428c-9564-b93e7cff6769.filesusr.com/ugd/510691_05389eb5edd24293b27ddc85e92ebf6c.pdf?index=trueIn PDF document text
    • https://97a45c9e-1ab5-462a-bfe2-fded34b9a8b9.filesusr.com/ugd/b50c55_dd297ff19034448e9e6096c9c0014c50.pdf?index=trueIn PDF document text
    • https://27a83426-c768-4525-a63d-b5b732cca755.filesusr.com/ugd/28b3f7_b1c7001ec08d4d7a867e59f4c17adcdc.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dae4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDAE4 5156 bytes
SHA-256: b382722b9838449b690e82bf1e6834f8b3ada7adbbff22cad91789de46be3c73
font_01_sfnt_off0000ec7b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC7B 10700 bytes
SHA-256: 39a2dff5796fd67d01446f811e35b6b06da9e7188201f1111ca508c17426ec42