Malicious PDF — malware analysis report

Static analysis result for SHA-256 503d028c6a6a820c…

MALICIOUS

PDF

75.0 KB Created: 2021-05-29 18:57:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-02
MD5: 7ed71630ff4c7f00204874e01a974f3f SHA-1: b99b7c4e71f8445b590a4df0ae79585e4ad324c6 SHA-256: 503d028c6a6a820c1939087ecae6b28c28fdf3ba00e6c0e374eefc6ed91d6996
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains numerous embedded URLs, many pointing to disposable hosting and employing UTM parameters, indicating a link farm designed to redirect users to potentially harmful sites. The document body, though heavily garbled, suggests a lure related to educational materials.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=libro+estrategias+de+ense%25C3%25B1anza+aprendizaje+del+autor+julio+pimienta PDF link annotation
    • https://zubikazosiz.weebly.com/uploads/1/3/4/7/134761183/bidebi.pdfIn PDF document text
    • https://lasemekesote.weebly.com/uploads/1/3/4/3/134314396/ketitanimiwevu.pdfIn PDF document text
    • https://zanewodibamejat.weebly.com/uploads/1/3/0/9/130969445/zudaba.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4411919/normal_6020cdc545d9b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4378382/normal_6064ce759a9ee.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379222/normal_60589fe504a72.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4421350/normal_5ff9ee7d1b24a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4463002/normal_60604f03a67af.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365606/normal_60484a045723d.pdfIn PDF document text
    • https://dasatupulike.weebly.com/uploads/1/3/4/1/134131314/dobaliturufivimobuza.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4386094/normal_601a64e27b669.pdfIn PDF document text
    • https://ferodamogeko.weebly.com/uploads/1/3/5/3/135330017/7a2ab1a5aeee4db.pdfIn PDF document text
    • https://nesaresivegixan.weebly.com/uploads/1/3/1/4/131453215/pubebamiganijixo.pdfIn PDF document text
    • https://kizatoruzosij.weebly.com/uploads/1/3/0/9/130969146/4686396.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/6f5f6230-67e2-4ea9-a523-d1e7754cb16f/normal_sat_essay_score.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7491cd6e-5371-429d-873b-19d7476bb9b4/divx_vod_code_registrieren.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4194043d-d306-45ba-8290-d0ee40ed18bc/dragon_ball_z_ttt_ppsspp_download_highly_compressed.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a5be6adf-e9e7-417d-9212-e80749bba7e1/10_challenging_interview_questions.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/40113d60-cb0d-4f0b-a7e8-e1c7ef41e60f/the_selection_movie_full_cast.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e0abe79b-c1f7-480c-9abd-a6141fc08c7b/11166392677.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/43b541c3-46ca-4a03-894d-db8256c1b4b8/power_wheels_dune_racer_reverse_not_working.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cb8b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCB8B 5700 bytes
SHA-256: 2f196b18b500dff03563273ede5f32de0c43806412768014e5a6065e1334e192
font_01_sfnt_off0000dea1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDEA1 11916 bytes
SHA-256: a1a9d7c627992bc0bfb540735d6b86894a6d6aea854904f24aeebafa36498934
font_02_sfnt_off00010597.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10597 16140 bytes
SHA-256: 5bfda07072dd2e1b0df7f1680a75ba616774ec51e1a09c257f000ba239241e1c