Malicious PDF — malware analysis report

Static analysis result for SHA-256 55628907d75b1004…

MALICIOUS

PDF

80.6 KB Created: 2021-04-06 08:08:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d80aebdf79d858d7b4cd16a09ca4c8b9 SHA-1: 53dde6904fdafc0efab74cec458d17d3fa28c6ec SHA-256: 55628907d75b1004e4067df9bbf724c7b4d62efdc04713a5867698e833bd9bdb
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM', suggesting a malicious intent to manipulate search engine results or redirect users to malicious sites. The ClamAV detection and ML classifier further support its malicious nature, classifying it as a phishing trojan. While no scripts were explicitly extracted, the presence of numerous URLs indicates a likely attempt to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=acls+experienced+provider+manual+pdf+download
    • https://cdn.sqhk.co/vawupemowa/7s4IjiO/binonepo.pdf
    • https://cdn.sqhk.co/tinulafi/aiaFNhH/zenozinoga.pdf
    • https://fevebelok.weebly.com/uploads/1/3/4/0/134012800/datadafezotu.pdf
    • https://pudosibax.weebly.com/uploads/1/3/5/9/135964381/govarukevosetit.pdf
    • https://notaxivarem.weebly.com/uploads/1/3/4/6/134633458/vikuto.pdf
    • https://cdn.sqhk.co/nukuzulu/N2Uwqgj/84739910767.pdf
    • https://vubufuzavedorav.weebly.com/uploads/1/3/4/7/134766784/dawon.pdf
    • https://cdn.sqhk.co/letarezetap/BgfBgji/jidetur.pdf
    • https://cdn.sqhk.co/rarinuva/mzjharC/brazil_champion_of_the_american_cup.pdf
    • https://tutemedoz.weebly.com/uploads/1/3/2/8/132814241/zekiloposusedu_marelapowenukol.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zevebetuj.epizy.com/59440591045.pdf
    • https://9cf93ecd-64ee-4ad6-afcc-f350577a7522.filesusr.com/ugd/c4dbd3_ac3463061b24422389d8c0ff21896e72.pdf?index=true
    • https://443275ec-395d-4f86-84c9-2ed7a250e117.filesusr.com/ugd/7d471d_032153d3a36c403d85db10c13baabce4.pdf?index=true
    • https://9334512a-4df1-45dc-8804-f0fa1d9e2a3d.filesusr.com/ugd/9466eb_1c4abfdd48f14605a070b21f6be4063c.pdf?index=true
    • http://rokidibamufoduv.epizy.com/que_medios_de_comunicacion_hay_en_la_actualidad.pdf
    • http://refuziw.epizy.com/solu_medrol_medication_guide.pdf
    • https://8137cd1e-393d-4948-8193-eca935452849.filesusr.com/ugd/756799_522002cdb780448eb52e32627d61ce47.pdf?index=true
    • https://09ec9d85-9312-4337-94d0-b84080e05f2e.filesusr.com/ugd/ac0094_ec8f75124dc7410f803614856b077859.pdf?index=true
    • https://49b821e7-ee7e-41b4-809b-d0417b8c1ddf.filesusr.com/ugd/927743_1cfabb30a5e041a2a5b8dfa9abad5a03.pdf?index=true
    • http://legofovivaxom.epizy.com/electricity_and_magnetism_guided_notes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000faa6.bin
1af3841ab6aed41362d401fa1a8a1b1d8466371ade3548d68ebf1a9abae1d8a6
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAA6 5512 bytes
font_01_sfnt_off00010d64.bin
5ee175a0d17429d41235da260c7e57fa8aa1bd4f46d0883f2d7ed47725a2364c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D64 11908 bytes