Malicious PDF — malware analysis report

Static analysis result for SHA-256 5dfcce1555b1f4ed…

MALICIOUS

PDF

76.2 KB Created: 2021-02-27 11:18:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9edb1e158cd72ac36556593c5df959f5 SHA-1: d5413d6f8660d308d1b6be48b0f77787b679b1f9 SHA-256: 5dfcce1555b1f4edc850204c90ca1a48809e7fcb2c291188b21b48eb10246419
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which appear to be SEO-driven, suggesting a link farm or phishing attempt. The presence of a ClamAV detection for 'Pdf.Phishing.Trojan' and ML classification further supports malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous embedded URLs indicate it's designed to redirect users to malicious sites, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=time+warner+-+spectrum+cable+lexington+ky
    • http://hempmap.ru/jurnal_terapi_bronkopneumonia_pada_anaka475k.pdf
    • https://jutegejedexugak.weebly.com/uploads/1/3/5/3/135384922/5769482.pdf
    • https://cdn-cms.f-static.net/uploads/4497359/normal_6013593375f9a.pdf
    • http://izzzaaa.space/swiftkey_pro_apk_full4hrd4.pdf
    • https://static.s123-cdn-static.com/uploads/4456686/normal_5fef990348d9d.pdf
    • https://cdn-cms.f-static.net/uploads/4463002/normal_6025c6abcce91.pdf
    • https://cdn.sqhk.co/xekejegixawo/vjighkb/21866507749.pdf
    • https://cdn-cms.f-static.net/uploads/4403260/normal_5fd1092fbf7b9.pdf
    • https://static.s123-cdn-static.com/uploads/4497344/normal_5fc98c10e091e.pdf
    • http://fbdirect.site/ways_to_listen_to_music_offline_free8z4cs.pdf
    • https://static.s123-cdn-static.com/uploads/4493245/normal_5fcaf7b99ca3a.pdf
    • https://poxemitiwafu.weebly.com/uploads/1/3/1/8/131871555/mizebusare.pdf
    • https://static.s123-cdn-static.com/uploads/4452588/normal_5ff57da87d202.pdf
    • https://wikiredapitij.weebly.com/uploads/1/3/2/7/132712416/2652802.pdf
    • https://static.s123-cdn-static.com/uploads/4461485/normal_5fca7e8bb31a0.pdf
    • http://marketitaly.info/7027326948fcb4v.pdf
    • https://cdn-cms.f-static.net/uploads/4366652/normal_600fc2b3e02d8.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebe5.bin
4bc125432e27527ad9a51ee32d4556bf5364bc73c23e710ef332a77315035040
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBE5 5700 bytes
font_01_sfnt_off0000ff56.bin
f3b4000e0ee2b4b8cd3aa27c96852ec5905f94f1ac4aacb7c677c985d502971d
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF56 10460 bytes