Malicious PDF — malware analysis report

Static analysis result for SHA-256 573ac5574bc231f6…

MALICIOUS

PDF

78.3 KB Created: 2021-05-20 05:31:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 95a7b536e596d2463e05d99c139ed1a9 SHA-1: 3e993542037cf860306178198adb06b54300d764 SHA-256: 573ac5574bc231f676c1e3b48a9495fb19f776a5b42963ed993354ef7bb9472a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many pointing to Weebly-hosted PDFs, suggesting a link farm or redirection scheme. The heuristic PDF_SEO_LINK_FARM indicates a large number of such links. The ML classifier and ClamAV detection strongly suggest malicious intent, likely phishing or a scam, by directing users to potentially harmful sites like 'dugedepap.ru'. No scripts were extracted, but the extensive use of external links is a primary indicator of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/strik?utm_term=custom+content+for+sims+4+mac
    • https://fakazurirogedim.weebly.com/uploads/1/3/4/7/134743668/82dd8384f1a81ce.pdf
    • https://jakipafowikodo.weebly.com/uploads/1/3/1/0/131070805/1765749.pdf
    • https://luxatowukubise.weebly.com/uploads/1/3/7/5/137508256/3323c1502.pdf
    • https://sagudazotimoja.weebly.com/uploads/1/3/4/7/134753003/691964.pdf
    • https://vebafuxitupum.weebly.com/uploads/1/3/4/8/134890404/9606bbc444bc.pdf
    • https://vipuwajaziw.weebly.com/uploads/1/3/5/3/135398090/9650304.pdf
    • https://lezanixopedem.weebly.com/uploads/1/3/4/8/134886347/1271484.pdf
    • https://besivopu.weebly.com/uploads/1/3/4/7/134705308/nekof.pdf
    • https://lexawuvake.weebly.com/uploads/1/3/4/6/134610488/fazup.pdf
    • https://fekazivijiwawad.weebly.com/uploads/1/3/4/6/134687088/vovuworisajimagiv.pdf
    • https://xegadoponuxi.weebly.com/uploads/1/3/0/7/130775279/2457875.pdf
    • https://kebomekol.weebly.com/uploads/1/3/5/3/135349545/4076752.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/8f5422a5-fa3c-4702-b492-0f798fb23a39/list_of_sins_in_the_bible.pdf
    • https://uploads.strikinglycdn.com/files/73485fbe-dc1d-43c1-8a33-dd132cdb4fb2/verizon_managed_security_services_gartner.pdf
    • https://uploads.strikinglycdn.com/files/6194e478-97c8-4524-9567-ceaf6408516d/how_much_does_a_finance_manager_earn_uk.pdf
    • https://s3.amazonaws.com/fadupazageraf/acrylic_mirror_sheet_uk.pdf
    • https://uploads.strikinglycdn.com/files/5685eb4f-36a0-4d3d-8ea4-0ee4a727bca2/tovilakewozefibozajavamub.pdf
    • https://uploads.strikinglycdn.com/files/6de58658-57a8-49f5-98dc-cf19c8c5963c/kugav.pdf
    • https://uploads.strikinglycdn.com/files/ec627561-bf2b-4c30-a699-bea36e20f127/tamutejapowaviko.pdf
    • https://s3.amazonaws.com/mukutud/3736629091.pdf
    • https://uploads.strikinglycdn.com/files/b8090c95-a735-4507-9246-d97680ec8853/dunuseroles.pdf
    • https://uploads.strikinglycdn.com/files/791e7634-39e5-4702-9041-88df02599cba/what_is_an_example_of_a_hyperbole_poetry.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e881.bin
b7536b71ab6cdac93bb3e81358b8b92a1359b7a342b8d255c3ba02f6b6e01f51
pdf-font-stream PDF embedded font (sfnt) at offset 0xE881 4988 bytes
font_01_sfnt_off0000f961.bin
831491a9054b6da367b0c9ac094c84b597a1ba2b6d414069d577e9876fae3719
pdf-font-stream PDF embedded font (sfnt) at offset 0xF961 10564 bytes
font_02_sfnt_off00011d82.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D82 4324 bytes