Malicious PDF — malware analysis report

Static analysis result for SHA-256 5940d14528ef552f…

MALICIOUS

PDF

81.2 KB Created: 2021-03-30 20:12:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 094905dc3fa0acbe0800dcbf3fd64a91 SHA-1: e1f7776217fcdb39e75667e91738e040261f8014 SHA-256: 5940d14528ef552f41c8bdd3bb3a8762116a7c703eb5420978f0353edfc7d545
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, indicating a link farm designed to direct users to potentially malicious websites. The heuristic 'PDF_SEO_LINK_FARM' and the presence of many URLs strongly suggest this malicious intent. Although no scripts were extracted, the PDF's structure and embedded URLs are indicative of a phishing or malware distribution campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=degrees+of+comparison+of+adjectives+rules+pdf
    • https://cdn.sqhk.co/nizivatitogu/GJigSRV/54954869060.pdf
    • https://cdn.sqhk.co/fawabanof/jcgfqO5/27010724196.pdf
    • https://cdn.sqhk.co/jugomuzuteb/ELjbqge/23804017087.pdf
    • https://cdn.sqhk.co/jiwosowo/OCjd4jg/94362049293.pdf
    • http://lesoxagepisubaw.iblogger.org/robin_hood_2010_movie_trailer.pdf
    • https://cdn.sqhk.co/nefakovuwot/jcibiiw/zukanetenurewu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://sebipukavore.epizy.com/32907732416.pdf
    • https://s3.amazonaws.com/jemisajoda/xowubamebupogafejir.pdf
    • https://uploads.strikinglycdn.com/files/6a1a1f43-3ea5-4b2c-bb82-6bbca9d31b88/figitowolikelapepaz.pdf
    • https://s3.amazonaws.com/jovekus/lajadomatu.pdf
    • https://d5fb4b5d-766d-4e54-ab1c-ecc61d2b7d82.filesusr.com/ugd/b0c8dc_f5ee0b6ab72b4dfcb951361a9caceef8.pdf?index=true
    • https://045423f6-c0c0-4d84-ad86-85f1ea38791a.filesusr.com/ugd/738632_b7bac27967784904b39494757a20e65a.pdf?index=true
    • https://s3.amazonaws.com/baxekojojexusol/29446475116.pdf
    • http://riporem.epizy.com/christian_worship_songs_malayalam_free.pdf
    • https://4cf6c2b4-cd84-4b73-83b1-bf7f441162b2.filesusr.com/ugd/e50c99_c5a3fa6bd74242ff94247983878acd33.pdf?index=true
    • https://uploads.strikinglycdn.com/files/d6279982-ee6c-42b3-a1b8-564d562ef19a/stihl_backpack_blower_br600_best_price.pdf
    • https://uploads.strikinglycdn.com/files/6f040d78-ec91-4cd8-8b80-38a24c72664a/what_is_a_toploader_transmission.pdf
    • http://jufosuliz.epizy.com/kbc_registration_todays_gbjj_question_and_answer.pdf
    • https://uploads.strikinglycdn.com/files/d1cfc107-0959-4b87-b88b-37d7e5511b5f/how_to_answer_questions_for_employee_self_appraisal.pdf
    • https://01c19f78-c7d0-441a-b56a-8672493f87de.filesusr.com/ugd/9d66c7_5d98fd55c53149aca537742c4da3f564.pdf?index=true
    • https://d848e4b6-662b-4424-a759-963270729452.filesusr.com/ugd/30e015_57520f26545b418f8cfa0a4cdea65b62.pdf?index=true
    • https://s3.amazonaws.com/gonima/zanupumufugoxok.pdf
    • https://s3.amazonaws.com/lepefi/new_bollywood_movie_2019_filmyzilla.pdf
    • http://novoboninixeme.epizy.com/perpendicular_bisector_theorem_worksheet.pdf
    • https://s3.amazonaws.com/fulosobezur/aim_trainer_pro.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001000c.bin
0edd8ee95d2864b4491d795400d6fe1670f938f5daa408ec7bc9abb615904483
pdf-font-stream PDF embedded font (sfnt) at offset 0x1000C 5612 bytes
font_01_sfnt_off00011325.bin
0cd3c615f50b7c4b4797a2f4dabd705cb12b9708207fc79e6ae1c1d80a5a36c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x11325 10532 bytes