Malicious PDF — malware analysis report

Static analysis result for SHA-256 53f8f5ec7652b62d…

MALICIOUS

PDF

70.9 KB Created: 2021-03-18 14:43:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e7f252d11a9407544980c349615ae5e6 SHA-1: d8795498ec21cc9f658231dee8471e4afcf83acd SHA-256: 53f8f5ec7652b62db71d50668bad50ae5d3468870e06f47e1c7068fb62e50af9
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which are disguised as educational resources. The ClamAV detection and ML classifier indicate malicious intent, likely for phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and numerous embedded URLs suggest an attempt to redirect users to malicious content, potentially leveraging embedded JavaScript for obfuscation or execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8673

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/award?keyword=map+of+the+world+countries+pdf
    • http://tojuvapemupo.mywebcommunity.org/educational_psychology_questions.pdf
    • http://sepoxudozixo.sportsontheweb.net/74726789386.pdf
    • https://fafefojesuvun.weebly.com/uploads/1/3/4/6/134651362/441789.pdf
    • https://woduluzotuni.weebly.com/uploads/1/3/4/3/134373450/045eceba.pdf
    • https://zemutixo.weebly.com/uploads/1/3/4/8/134865820/fokis.pdf
    • http://pifemukopisare.sportsontheweb.net/java_swing_mysql_connection_example.pdf
    • http://wusator.mygamesonline.org/fotemojunavovasakosem.pdf
    • https://cdn-cms.f-static.net/uploads/4381988/normal_6023fff622706.pdf
    • https://xomitemekebok.weebly.com/uploads/1/3/4/8/134881854/pigoliguwujosadido.pdf
    • https://cdn-cms.f-static.net/uploads/4495685/normal_60102c0af074d.pdf
    • https://fiwozipuwawew.weebly.com/uploads/1/3/0/8/130814157/vomenetitinuke-dukorobalujefi-lidixerizune-tavipakiluvemon.pdf
    • https://cdn-cms.f-static.net/uploads/4427274/normal_6051495fcd61d.pdf
    • https://latifaxegorur.weebly.com/uploads/1/3/5/4/135400737/5b9aae6ff3.pdf
    • https://leximefowa.weebly.com/uploads/1/3/2/6/132680903/9772870.pdf
    • https://static.s123-cdn-static.com/uploads/4390661/normal_5febea82ea7a6.pdf
    • https://static.s123-cdn-static.com/uploads/4370778/normal_6007d87c974f2.pdf
    • https://wobikuneli.weebly.com/uploads/1/3/2/7/132741052/f58609a.pdf
    • http://gujozulogisin.scienceontheweb.net/88484794153.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://28546a20-d0cc-4b82-bb4f-6711990cd5a3.filesusr.com/ugd/0bcf16_0a63a5e923ec4d4095b29bcf178cc156.pdf?index=true
    • http://lagamifex.epizy.com/applying_angle_relationships_homework_2_answers.pdf
    • https://f11c4bf2-12a6-49f8-9590-07a94b689168.filesusr.com/ugd/11276f_54389d4a860e4b6bb64dfd0c9034c5ef.pdf?index=true
    • https://f61a8d15-835b-4c36-a3db-e4ead73ab13f.filesusr.com/ugd/e9f5f3_e1f3819948504aaf8c20abeb53303ffe.pdf?index=true
    • http://janojunotoz.epizy.com/2012_jeep_grand_cherokee_limited_transmission_problems.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000de79.bin
c36fd193c301302c7d06a1f475232211969cd6a9fd650a2f431185ad4e6d6419
pdf-font-stream PDF embedded font (sfnt) at offset 0xDE79 5220 bytes
font_01_sfnt_off0000f046.bin
6698316ebc917987e539a4c74a01ab4555e866b7f80d3a535b145b601242727a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF046 10584 bytes