Malicious PDF — malware analysis report

Static analysis result for SHA-256 5465bd5087bbbf9f…

MALICIOUS

PDF

96.8 KB Created: 2021-03-19 06:05:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2b6baece15951c7eddca83146f24dade SHA-1: d3985244f3d9bc750a9c120348bfd5fc4bf22ae3 SHA-256: 5465bd5087bbbf9f24646e474fa642923ff152e908920e4c4f69507dd1230ee5
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are to PDF files, suggesting a link farm or SEO manipulation tactic. One prominent URL, 'https://jacksth.ru/strik?utm_term=roman+empire+flag+spqr', is directly embedded and appears to be a malicious domain. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=roman+empire+flag+spqr
    • https://cdn-cms.f-static.net/uploads/4447877/normal_60526710011a3.pdf
    • https://cdn-cms.f-static.net/uploads/4428331/normal_601ba74f2c6a3.pdf
    • https://static.s123-cdn-static.com/uploads/4406775/normal_5feb0e53c99de.pdf
    • https://cdn-cms.f-static.net/uploads/4470211/normal_604cdb5b00730.pdf
    • https://wezusutuxalik.weebly.com/uploads/1/3/1/6/131637092/8f6c20a864.pdf
    • https://cdn-cms.f-static.net/uploads/4372378/normal_6023fb320131c.pdf
    • https://cdn-cms.f-static.net/uploads/4369797/normal_604c9e5299e12.pdf
    • https://jukuxalubena.weebly.com/uploads/1/3/1/4/131453985/kosix-juxeriz-refevitaziwesob.pdf
    • https://cdn-cms.f-static.net/uploads/4448746/normal_603cc9703d8f1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/dc2d834b-c4f7-4861-875b-4492c769e240/86799385511.pdf
    • https://2386e270-bd20-42c1-b3e5-1ba7eaa1d68d.filesusr.com/ugd/b4f0c6_cb5e52b9874c45b99862532fe5f74cf6.pdf?index=true
    • http://sofopemesojume.epizy.com/kubikojuvavujop.pdf
    • https://uploads.strikinglycdn.com/files/a7d3d9d3-74e1-4e56-92e4-62d25af1692a/keurig_k_cup_holder_replacement_bed_bath_and_beyond.pdf
    • http://jipudovisubu.rf.gd/c_lambda_template_parameter.pdf
    • https://uploads.strikinglycdn.com/files/4aa1053b-5704-4f43-afaa-54509ece501e/pafadaludewapatibajositow.pdf
    • https://41c240d9-b4af-4f88-8fa4-2a41cce3a287.filesusr.com/ugd/01bc73_c25ea6515bcc42468e7c0b10e46de7e2.pdf?index=true
    • http://tesusaruva.epizy.com/metformin_causes_bubbles_in_urine.pdf
    • http://gitobunubi.epizy.com/frases_nominales_en_ingles.pdf
    • https://d86ad34a-7df2-4f47-937b-a12ab5abc0fa.filesusr.com/ugd/8cbfce_79472db4398b49acbdd214739c31a7d3.pdf?index=true
    • https://uploads.strikinglycdn.com/files/2d7d865b-aa5e-4880-b7ad-ddb23e622ed2/how_long_bradford_white_water_heater_last.pdf
    • http://vulamexi.rf.gd/dikibulijogiwosoko.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001296c.bin
945631315962f2fc43552cf43aa1becc9c9f0401c49a57ca8c604d9c04123c6e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1296C 5064 bytes
font_01_sfnt_off00013a7b.bin
4f4409febf58c7c5d8118e84a95ec2e51b9a85cc39d36a3bd164e0e461fdf7bc
pdf-font-stream PDF embedded font (sfnt) at offset 0x13A7B 14064 bytes
font_02_sfnt_off000165bb.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x165BB 4324 bytes