Malicious PDF — malware analysis report

Static analysis result for SHA-256 5cab5807413548b9…

MALICIOUS

PDF

121.2 KB Created: 2021-04-14 17:07:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 17a81ab976ec4d492a7983f65c03a2de SHA-1: a7f9e4ba4e34773aa45cfa5d67027dc788e370e0 SHA-256: 5cab5807413548b9a604bf3c8f86e070fe8698204a5a83299fe5da2d736ada2b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. It contains a large number of external links, many of which point to potentially malicious domains, suggesting a link farm or phishing attempt. The primary malicious URL identified is https://nipisod.ru/strik?utm_term=the+importance+of+being+earnest+pdf, which is likely used to distribute further malware or conduct phishing operations.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=the+importance+of+being+earnest+pdf
    • https://cdn.sqhk.co/nizekidido/ntOr0gf/vba_datetime._date_format.pdf
    • https://cdn.sqhk.co/jezuleku/jcyUmVN/classic_chess_games_annotated.pdf
    • https://minadefimufev.weebly.com/uploads/1/3/4/6/134635785/deregavijeridun.pdf
    • http://koponegigat.medianewsonline.com/34459678845.pdf
    • https://cdn.sqhk.co/sadirorig/bMHzfA2/aaron_rodgers_family_fallout.pdf
    • http://wabiferofuvud.mygamesonline.org/public_policy_analysis_models.pdf
    • https://cdn.sqhk.co/senuziker/NEjbjcD/bmx_boy_game_free_download.pdf
    • https://nikulagoronol.weebly.com/uploads/1/3/2/3/132303117/05e47b9d56577c.pdf
    • http://zakosemej.mypressonline.com/kewitepetuwufizid.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/84b6f340-58b1-486a-9902-c40672bd2049/burger_king_breakfast_hours_start_time.pdf
    • http://rogofideb.onlinewebshop.net/characteristics_of_financial_services.pdf
    • https://uploads.strikinglycdn.com/files/e3cf27e7-83e1-4ab8-b571-5e333e4565f6/56757926189.pdf
    • https://536432c6-7160-4795-b32c-faef63afc1c8.filesusr.com/ugd/5e2347_395148b21b024a6ea7485f0fa8e21b69.pdf?index=true
    • https://40ba1f7a-6e91-49bb-bbb8-dfbb40a2bc60.filesusr.com/ugd/22bf55_1727725f6a0c4307b48ad533736165e4.pdf?index=true
    • http://rotufixijisadi.onlinewebshop.net/62630933939.pdf
    • https://58f604bd-1fd8-4cfe-af9b-f15e67d030d5.filesusr.com/ugd/9a7439_77d3436541fa4bf7b84bcdf27284a503.pdf?index=true
    • https://uploads.strikinglycdn.com/files/44aed571-6c6b-47e7-a241-dcadf655d63a/85799326931.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00019cdd.bin
6a6340dfd873d4aec2b82d218de37a44e8cc8eda15d1d88100af9e8e77e654b9
pdf-font-stream PDF embedded font (sfnt) at offset 0x19CDD 5624 bytes
font_01_sfnt_off0001afcb.bin
733ed8058ab982a7266281164afddd31590842b3552367f40a97ac57cefca764
pdf-font-stream PDF embedded font (sfnt) at offset 0x1AFCB 11872 bytes