Malicious PDF — malware analysis report

Static analysis result for SHA-256 8f53db0642f33ff6…

MALICIOUS

PDF

82.7 KB Created: 2021-03-24 22:01:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dd5f5e425121b7f69244bed2f9babc60 SHA-1: db153b45e9074cc2cc887371752cd4e28aaf5b0c SHA-256: 8f53db0642f33ff6528f7a27d0373826d0282ba465189c068c8b4bd51e9c1255
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with one specifically pointing to a URL that appears to be part of a link farm designed to distribute SEO-optimized PDFs. The ML classifier and ClamAV detection strongly indicate maliciousness, likely related to phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to redirect the user to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/123?utm_term=economically+weaker+section+form+in+gujarat
    • http://tugokutuli.scienceontheweb.net/8865625702.pdf
    • https://dupukaradox.weebly.com/uploads/1/3/6/0/136015529/bawuf.pdf
    • https://pixasowurixes.weebly.com/uploads/1/3/4/9/134904492/vewimef-fokufogomoj-vituvofifopodu.pdf
    • https://cdn.sqhk.co/vuluzazogur/teif8gc/marvel_future_fight_wiki_epic_quest.pdf
    • https://suzulazupe.weebly.com/uploads/1/3/3/9/133997697/ce5a1.pdf
    • https://cdn.sqhk.co/sezabaxo/wjaiRja/red_herring_prospectus.pdf
    • https://powufekati.weebly.com/uploads/1/3/4/0/134012492/sawasavigopip_jabozonodinoj_dupowekuposo_xudaguz.pdf
    • http://linodogeb.scienceontheweb.net/preface_to_lyrical_ballads_1802_william_wordsworth_summary.pdf
    • http://kazexajisodibu.medianewsonline.com/tableau_activation_key.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/zidenigad/boveluvije.pdf
    • https://s3.amazonaws.com/farefasejikap/guvodumipawozoxawenap.pdf
    • https://s3.amazonaws.com/janodojivi/37056155360.pdf
    • https://uploads.strikinglycdn.com/files/f094040a-3086-4fa0-8fac-7f54481b48c1/kubota_spare_parts_catalogue.pdf
    • https://6c71f620-b6e5-46cc-9e58-526c5f0a7a41.filesusr.com/ugd/1c90dc_32104ec723fc4e949a3974588a0348c8.pdf?index=true
    • https://s3.amazonaws.com/sepovutapakogaf/fejepufefapisirelolasi.pdf
    • https://uploads.strikinglycdn.com/files/02189f82-48c1-4ac1-a1a0-e6a104ab0bc0/how_to_read_an_ekg_for_beginners.pdf
    • https://s3.amazonaws.com/gagotaniwipure/basic_tactics_for_listening_tapescript.pdf
    • https://34184745-b1ec-4725-b105-60c94cc90871.filesusr.com/ugd/63369f_572872a417bd4d048f9b8c3cfc5e33c0.pdf?index=true
    • https://178fd8f3-986e-459b-a431-83c1f58eadb8.filesusr.com/ugd/7a8e82_ae457929af404c66990b96147902762b.pdf?index=true
    • https://uploads.strikinglycdn.com/files/89a80bfa-dea9-46c6-87fe-795d6c9b3841/thule_bike_rack_lock_instructions.pdf
    • https://uploads.strikinglycdn.com/files/08ec2fa1-487e-49db-813e-6822a2916d79/30911171003.pdf
    • https://74fc1a11-d445-4ffb-bc6b-7a79e5a65a18.filesusr.com/ugd/097bd5_988cc6d392a440959faf70c3f8fb86a1.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e329.bin
0fcef192c95d6fd4d5333de3e5f0a04c8525a73f6e29f4febd37223f58d6e746
pdf-font-stream PDF embedded font (sfnt) at offset 0xE329 3080 bytes
font_01_sfnt_off0000ee32.bin
3b3b6b64fe55b4d2feb14d329380525fb86d2ecb134403b9a5f973ff1a706303
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE32 5492 bytes
font_02_sfnt_off000100ed.bin
5f5b7037f6d1300fd5c1ae043ef06bceff379d0be80b15b7e294401112783e9c
pdf-font-stream PDF embedded font (sfnt) at offset 0x100ED 10596 bytes
font_03_sfnt_off00012580.bin
461a1578f80084b2f2ca998a6e716936969cc9b33b2976d66eaaa57f6abee57a
pdf-font-stream PDF embedded font (sfnt) at offset 0x12580 16172 bytes