Malicious PDF — malware analysis report

Static analysis result for SHA-256 93a5e2d213518afd…

MALICIOUS

PDF

132.5 KB Created: 2021-03-25 02:46:28 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 256001501792d45e6cc83d6993b8cd30 SHA-1: e966a602b6ffc2590dff1b237d3368293ba8c1e3 SHA-256: 93a5e2d213518afdac7133be2e05c6ec07723a442e07059c7ad3e1ca6bca5bcb
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file is identified as malicious by ML classifiers and ClamAV, indicating a phishing or malware distribution attempt. It contains a large number of external links, many of which are likely part of a link farm designed to improve search engine rankings for malicious content. The primary URL, 'https://nipisod.ru/wix?keyword=naruto+shippuden+manga+volume+1+pdf', suggests a lure related to popular manga, aiming to attract users searching for such content. No scripts were extracted, but the PDF structure and numerous external links point towards an attack pattern focused on redirecting users to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=naruto+shippuden+manga+volume+1+pdf
    • https://mamumudud.weebly.com/uploads/1/3/0/8/130814078/f45b31c.pdf
    • https://lopenedaxi.weebly.com/uploads/1/3/1/6/131606218/tekatubixonapil.pdf
    • https://malafusid.weebly.com/uploads/1/3/2/8/132815748/galizora-xefefavelutowor.pdf
    • https://cdn-cms.f-static.net/uploads/4459058/normal_603a5e07b77b1.pdf
    • https://cdn-cms.f-static.net/uploads/4426955/normal_60187cd189ad5.pdf
    • https://cdn-cms.f-static.net/uploads/4375199/normal_6015ff6a6b902.pdf
    • http://lebizifijafaxim.medianewsonline.com/data_science_bootcamp_dc.pdf
    • http://xomerisupudegop.medianewsonline.com/fefoladukevut.pdf
    • http://dugarudewemudo.sportsontheweb.net/area_and_perimeter_of_rectangles_word_problems.pdf
    • https://davijune.weebly.com/uploads/1/3/5/3/135315517/xupatamokelopi.pdf
    • https://cdn-cms.f-static.net/uploads/4421960/normal_605355dc4af30.pdf
    • http://xijivedijimidip.mygamesonline.org/16698451246.pdf
    • http://rerixen.scienceontheweb.net/xokalusola.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/e3e9dc4e-5092-4603-92ae-90bb1ee8bf22/bekugipulenapesafiripow.pdf
    • https://uploads.strikinglycdn.com/files/889087bf-1cea-4385-a340-931b5ce039d7/nanojixoxazafa.pdf
    • https://uploads.strikinglycdn.com/files/2f135b17-335c-4175-af6f-2b9cc0ad356c/qurani_ayat_with_urdu_meaning.pdf
    • https://s3.amazonaws.com/tokatefozude/60524766071.pdf
    • http://xerekexaxo.epizy.com/c_for_dummies_all_in_one.pdf
    • https://s3.amazonaws.com/wajufifenoxuj/67675987199.pdf
    • http://kobuxeniduf.rf.gd/zigegevipimomegesugene.pdf
    • https://s3.amazonaws.com/bikikanafopavu/89686396474.pdf
    • https://uploads.strikinglycdn.com/files/596b9b56-8d56-4212-8c8a-180ad611f657/who_has_the_slowest_40_yard_dash_in_nfl_history.pdf
    • https://uploads.strikinglycdn.com/files/6c2697b9-0ebe-404e-96c3-d6f1b6a8f840/lifad.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000105fd.bin
bb48712efa8dd18a139ea44ac692fef79b2862b4ee53e1267bbdb8044afc5356
pdf-font-stream PDF embedded font (sfnt) at offset 0x105FD 60804 bytes
font_01_sfnt_off0001be9b.bin
4c2e1f0d63e24b90889e0dd6401f750638b5d7085c5c8dcee9e103dcf6e548c8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1BE9B 5416 bytes
font_02_sfnt_off0001d0e9.bin
21b3b71ba87afb0bc66d1a81c823ad2675e596f63fe343a3bcf5dfea87e89b54
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D0E9 11408 bytes
font_03_sfnt_off0001f62b.bin
7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0x1F62B 4324 bytes