Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f5ed419d29ce684…

MALICIOUS

PDF

73.9 KB Created: 2021-03-23 22:35:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f30a9c55d3929c107cb850d1985f804c SHA-1: 7397da83df66be492be8436b1499322193157a0f SHA-256: 5f5ed419d29ce6841bf344b15c68312c5d008a28363fa2aa8cab2dcec9610b90
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a common tactic for phishing or SEO link farming. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as a phishing trojan. The embedded URLs, such as https://golowaki.ru/award?keyword=aptitude+shortcuts+and+tricks+for+placements+pdf, are likely used to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/award?keyword=aptitude+shortcuts+and+tricks+for+placements+pdf
    • http://salleapp.xyz/lowrance_elite_7_chirp_specsr3ghx.pdf
    • http://autolombardpro.ru/prelude_bwv_1006_guitarq692e.pdf
    • http://srakan.space/nubizojmd1a8.pdf
    • http://life50it.pro/rozanikeledodetigisokgc8t3.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/xuxifuzituwu/induction_motor_control_design.pdf
    • https://uploads.strikinglycdn.com/files/4b5daf31-d6df-41a5-93b2-9aa14b51025b/why_was_presidential_reconstruction_a_failure.pdf
    • https://s3.amazonaws.com/silubebebefuju/50360105564.pdf
    • https://uploads.strikinglycdn.com/files/d1eff104-9537-423f-b901-ab5fcd9ec0e3/how_long_do_die_hard_batteries_last.pdf
    • https://uploads.strikinglycdn.com/files/c829eb8b-9a6f-496c-9dbd-ae93c60b555f/4232062539.pdf
    • https://uploads.strikinglycdn.com/files/b6c90403-fe49-4f82-974c-b49afcbaf2a5/how_to_repair_ez_go_golf_cart.pdf
    • https://1dfef493-bba3-4db0-89f7-7cef958ceea2.filesusr.com/ugd/3dbeb3_b78bd75f77fe435e9fb9f31afc9ac550.pdf?index=true
    • https://s3.amazonaws.com/bisapovepizaj/61003420592.pdf
    • https://uploads.strikinglycdn.com/files/ee7f7838-cf17-4cbf-8ab9-4039544cdf27/how_do_you_find_number_of_atoms_in_a_compound.pdf
    • https://170a7d3c-74f0-42f5-9ead-98ae292a4922.filesusr.com/ugd/a18aa6_3397e2f574014916be5de03de76e6bd3.pdf?index=true
    • https://35b1a599-9f45-4897-82ce-59a931fc5495.filesusr.com/ugd/daca0d_c0ba6ca71c7e49aeb46d686dbe95c346.pdf?index=true
    • https://uploads.strikinglycdn.com/files/7f79062e-b9a2-442a-afe3-d8a2af3e7c23/troy_bilt_tb240_blade_adapter.pdf
    • https://uploads.strikinglycdn.com/files/ac53a0ed-15ed-4ddc-98be-5a17094d4b6a/31898418709.pdf
    • https://dd3528e8-ded0-4753-843e-0d3cb9f542e7.filesusr.com/ugd/4d6844_bee625ab34164733af706da2060025e3.pdf?index=true
    • https://uploads.strikinglycdn.com/files/82dd67a0-a0be-4c9b-bc51-3576d092d349/what_is_expense_and_revenue.pdf
    • https://uploads.strikinglycdn.com/files/4246e191-1473-4e2d-8074-347a65767da7/golopazanexuxiditi.pdf
    • https://a84030a7-2e48-4039-807a-383e2b7216cc.filesusr.com/ugd/c5d40f_7f455bed5e4f49a7aec68f13bde64a69.pdf?index=true
    • https://uploads.strikinglycdn.com/files/4115e0e1-a8c9-49c0-96e6-98ab6ad8b70f/keurig_k45_elite.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e22b.bin
08bd3d580acd379014e719941f4b9dc17c971ae0d2c36c9c226104a1d45c03df
pdf-font-stream PDF embedded font (sfnt) at offset 0xE22B 5448 bytes
font_01_sfnt_off0000f48c.bin
935c4e2648e3458b5a740bfdd87bfdd74ac2ed1c3de4894d13f7d79455af99fe
pdf-font-stream PDF embedded font (sfnt) at offset 0xF48C 11136 bytes