Malicious PDF — malware analysis report

Static analysis result for SHA-256 911df5c50546d96a…

MALICIOUS

PDF

71.2 KB Created: 2021-03-16 18:36:08 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 93da962ea5a1d14005d660416062d33d SHA-1: 121a36536af1e682f7bc5a73f6c90e6ae523abc5 SHA-256: 911df5c50546d96a47a545bf38e90f161a3ad30cd40d93c466e9066eff49572f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, forming a link farm, and is flagged by ClamAV as a phishing trojan. The primary URL, https://jumiwimov.ru/wix?keyword=dean+s+luce+school+calendar, suggests a phishing lure related to a school calendar. While no scripts were explicitly extracted, the PDF structure and heuristic firings indicate malicious intent to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=dean+s+luce+school+calendar
    • https://wefapewirevuvik.weebly.com/uploads/1/3/4/6/134667644/3758036.pdf
    • https://cdn-cms.f-static.net/uploads/4471238/normal_6029303ea9e5a.pdf
    • https://zumizosapozogem.weebly.com/uploads/1/3/2/6/132681504/775b76bdc47e.pdf
    • https://static.s123-cdn-static.com/uploads/4455902/normal_5fe53df9a673f.pdf
    • https://cdn-cms.f-static.net/uploads/4475212/normal_5fe9b01bea8e4.pdf
    • https://zufodivovogopot.weebly.com/uploads/1/3/1/3/131383523/togefezelipak.pdf
    • https://cdn-cms.f-static.net/uploads/4387939/normal_5fd6442ee5f29.pdf
    • https://static.s123-cdn-static.com/uploads/4481059/normal_5fc992a245bc6.pdf
    • https://ramosekizopozov.weebly.com/uploads/1/3/0/7/130740175/wuvumovak-toganezukugez.pdf
    • https://cdn-cms.f-static.net/uploads/4379970/normal_60152afb9e45d.pdf
    • https://finaxapiw.weebly.com/uploads/1/3/5/3/135301963/milobuzo.pdf
    • https://static.s123-cdn-static.com/uploads/4375194/normal_5fc732db9f658.pdf
    • https://cdn-cms.f-static.net/uploads/4376088/normal_603523cfa30a9.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/57343bc7-cb91-43f2-b7f5-05cacee0a6d1/how_much_is_a_catalytic_converter_for_a_2005_nissan_murano.pdf
    • https://uploads.strikinglycdn.com/files/20b9107b-2f93-4347-8c11-594f6bb09219/holmes_and_rahe_stress_scale_survey.pdf
    • https://uploads.strikinglycdn.com/files/79cbb9b3-71b6-4037-bc1b-94130be02bd7/98320689902.pdf
    • https://cad90261-f038-4e8a-b384-2e0e37e6cb8c.filesusr.com/ugd/4c4e45_1f66dd42cf6f4bf3a8c22de1c30cf61c.pdf?index=true
    • https://uploads.strikinglycdn.com/files/ccc44fef-8cc3-4732-88fe-b734eb6dd040/naxiv.pdf
    • https://uploads.strikinglycdn.com/files/d9091519-24c1-47e6-8a42-1d8bfa3a7425/8356144268.pdf
    • https://38f9ccf9-db33-4582-994d-0ea518e52d38.filesusr.com/ugd/368de4_c4547da541114fcb9c912e97f5620aca.pdf?index=true
    • https://uploads.strikinglycdn.com/files/7eff9ede-26d0-4ed2-93b4-285854f5d232/47966233694.pdf
    • https://4f0754e2-f0c4-47db-826b-83042027646c.filesusr.com/ugd/7a11b0_d307cb6665b245b99ee5f626175ebe09.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d682.bin
7a07e6e5a141abf0c5f98590266d57ed9b09ca43bbef563d80d48536318d64f9
pdf-font-stream PDF embedded font (sfnt) at offset 0xD682 5024 bytes
font_01_sfnt_off0000e790.bin
e027c2df2d8c9c40bae1697625e4f5d45dda8cb71f8ecde97e48cb21826186f9
pdf-font-stream PDF embedded font (sfnt) at offset 0xE790 11276 bytes