Malicious PDF — malware analysis report

Static analysis result for SHA-256 9bba05f9df01a842…

MALICIOUS

PDF

75.7 KB Created: 2021-03-27 15:15:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b9f0790bc51d57046814a4a89984f2bf SHA-1: 2676dd9244f1907faf6c36d0cda32c62b8a1ceab SHA-256: 9bba05f9df01a8423850691603e3545347788f57e6809549260e6b151172b244
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a large number of external links, suggesting it functions as a link farm for SEO manipulation, likely directing users to malicious websites. The primary malicious URLs identified are 'https://nipisod.ru/wix?keyword=nosotros+no+jose+bernardo+adolph+in+english' and 'http://zuzorovix.scienceontheweb.net/jizovirebaposiko.pdf'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=nosotros+no+jose+bernardo+adolph+in+english
    • http://zuzorovix.scienceontheweb.net/jizovirebaposiko.pdf
    • https://sewetupowak.weebly.com/uploads/1/3/5/9/135971958/75020b9b.pdf
    • http://bejisosubonito.sportsontheweb.net/ernhrungsplan_ketogene_dit.pdf
    • https://static.s123-cdn-static.com/uploads/4444386/normal_5fc6b82f4f65f.pdf
    • https://roserilufelojow.weebly.com/uploads/1/3/1/8/131856860/5731521.pdf
    • https://cdn-cms.f-static.net/uploads/4391314/normal_5fdc5a31c908a.pdf
    • http://fexevewuli.mypressonline.com/bagewowivirafibibegurafag.pdf
    • http://sollabs.xyz/60996253424zdvwe.pdf
    • https://momobalujinas.weebly.com/uploads/1/3/2/3/132303205/5e2116d974.pdf
    • https://kebonipima.weebly.com/uploads/1/3/0/7/130740513/9836977.pdf
    • https://static.s123-cdn-static.com/uploads/4428062/normal_5fc73ee06dbd0.pdf
    • http://velesvoyage.ru/equation_differentielle_a_variable_separable_exercices_corrigs96c9p.pdf
    • http://reduslim-ordina.site/vw_service_garage_cardiff2kbo7.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/d211284b-e5a4-4336-8b57-ed87b3aafa9d/tufagalutotuva.pdf
    • https://uploads.strikinglycdn.com/files/eeb65b83-9d1b-4a31-ba77-83a19ad58192/mikugivokadefabu.pdf
    • https://uploads.strikinglycdn.com/files/c65d0575-99c1-419d-b060-26f6307d7386/sapugodemogot.pdf
    • https://uploads.strikinglycdn.com/files/460e63eb-b941-4326-8678-bc0a1a7fdba0/tesla_model_3_performance_0-60_test.pdf
    • https://uploads.strikinglycdn.com/files/eef5db96-d482-4cbb-905b-0a5447f0df90/55896919669.pdf
    • https://ed21222e-fee3-4fab-8b52-e2ddb7bb35ab.filesusr.com/ugd/e73fea_eb25131b68524f80a4f959c377bf6f0c.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000daf7.bin
10a07fc969e6c8cf41398fcfefa625e426b29a45b33f3716d0886db1405c0d2a
pdf-font-stream PDF embedded font (sfnt) at offset 0xDAF7 2900 bytes
font_01_sfnt_off0000e53a.bin
b2aff1b45639a455d505ead47c23b047736c6539cb6943dfd0a52b2e01251a28
pdf-font-stream PDF embedded font (sfnt) at offset 0xE53A 5408 bytes
font_02_sfnt_off0000f798.bin
57c9dd85d77e5dde245f2ad7d808708ceb84c725d828e2f6246f14c94b6ed610
pdf-font-stream PDF embedded font (sfnt) at offset 0xF798 12100 bytes