Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b53edba54a5710b…

MALICIOUS

PDF

65.2 KB Created: 2021-03-13 22:18:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-17
MD5: 20cea7e6301ca69af06660436fc5ba3c SHA-1: fa4d0cdf6805a98c6b4d1334a38c54b6353adf6b SHA-256: 5b53edba54a5710be12a394af9732285c8a9c8f7620aab3174d5d6da78a964a5
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF document that contains multiple embedded URLs, with one specifically identified as a malicious external URI. The PDF_SEO_DISPOSABLE_LINK_FARM heuristic indicates a pattern of using disposable hosting for link farms, suggesting a phishing or spamming operation. The ML classifier and ClamAV detection strongly indicate malicious intent, likely to redirect users to a compromised or malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8603

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/award?keyword=administration+of+drugs+via+enteral+feeding+tubes+pdf PDF link annotation
    • https://cdn.sqhk.co/zoluxoni/ziaifgd/xexizosabesixamukebeded.pdfIn PDF document text
    • https://cdn.sqhk.co/zibomevuguli/Q9Tijz6/93711308750.pdfIn PDF document text
    • http://golden-charm.ru/philosophy_the_power_of_ideas_9th_editionvqr27.pdfIn PDF document text
    • https://luwibizikowar.weebly.com/uploads/1/3/4/4/134483868/7499062.pdfIn PDF document text
    • https://vofoxefak.weebly.com/uploads/1/3/4/6/134645633/8408247.pdfIn PDF document text
    • https://cdn.sqhk.co/dugelabomaw/Mhb7vLZ/7138937370.pdfIn PDF document text
    • https://cdn.sqhk.co/bomunerafoju/Cgd0QmQ/latest_android_software_update_2019.pdfIn PDF document text
    • https://cdn.sqhk.co/tujujelo/jgjdjgb/beep_codes_of_computer.pdfIn PDF document text
    • http://usesucre.pro/maxtor_onetouch_4_mini_software_downloadp61gv.pdfIn PDF document text
    • https://sibanomo.weebly.com/uploads/1/3/0/9/130969588/c4091.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/c7eafab4-c8e4-4845-8057-cf8016d7480d/7020918663.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/21521738-938d-451c-ad0e-be3f9656bcc8/roxunizexeki.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2da0b4cc-299c-4908-a33a-5a7c563b149e/88965410530.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9d6c1471-5151-4440-aeda-396b99c127ba/a_midsummer_nights_dream_modern_text.pdfIn PDF document text
    • http://maxeses.rf.gd/jemanavuwewizusowilubobe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8e7fd5a2-4f2e-4d32-be91-ad70aaf0dfe3/koxafigetuzibi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4569434c-a5ab-491d-9889-25edb5633002/cm_a_pulgadas_formula.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a46d690b-e17b-4070-93b6-11cce5758369/is_there_going_to_be_another_percy_jackson_series.pdfIn PDF document text
    • http://vifowas.epizy.com/18768127294.pdfIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e17c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE17C 5548 bytes
SHA-256: 62005497626f34cf1db33951973eba64c270fa3b64c9ffdf991b57487ce0f204