Malicious PDF — malware analysis report

Static analysis result for SHA-256 b435dc2e17195b1e…

MALICIOUS

PDF

77.5 KB Created: 2021-03-24 16:19:30 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c7bde101cbde356fef9d58e781d3d7da SHA-1: 52782a04a28cc1b6c99d9a266b460c45f85e96a5 SHA-256: b435dc2e17195b1ef9b2fd566b512789f396f4833e85289e61fc9e384226c2d1
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ClamAV as a phishing trojan and ML classifier indicated high maliciousness. It contains an embedded URI pointing to 'jacksth.ru', which is likely a phishing or malware distribution site. The document body, though truncated and obfuscated, suggests a lure related to 'award ceremony background music'. The presence of external URIs and the overall structure align with a phishing attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/123?utm_term=award+ceremony+background+music
    • https://cdn-cms.f-static.net/uploads/4488346/normal_6010d402c96ea.pdf
    • https://cdn.sqhk.co/raxoxawupej/hiiebji/school_management_system_using_linked_list_in_c.pdf
    • http://vomoliba.scienceontheweb.net/definition_of_health_psychology.pdf
    • http://kalowodopole.mygamesonline.org/go_math_8th_grade_textbook.pdf
    • http://raxejudesezix.scienceontheweb.net/35082502503.pdf
    • https://cdn.sqhk.co/juvanejejuwo/USpigja/wewadegexeka.pdf
    • https://static.s123-cdn-static.com/uploads/4414691/normal_600957add7b8a.pdf
    • https://cdn-cms.f-static.net/uploads/4366313/normal_5fd64af28c681.pdf
    • https://cdn.sqhk.co/tarekekog/eAgf4us/missing_411_hunters_movie.pdf
    • http://tozepefaj.iblogger.org/borurovilaruvadimalavub.pdf
    • http://nesorus.mywebcommunity.org/22832063020.pdf
    • https://cdn-cms.f-static.net/uploads/4467945/normal_6034e04dcbe8c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://154530d8-637b-49d0-b90a-43bf07a176fb.filesusr.com/ugd/59359a_ecd8a06b66a34135af789b7928987350.pdf?index=true
    • http://gajutar.onlinewebshop.net/magic_chef_dishwasher_filter_removal.pdf
    • http://dazulenaredon.rf.gd/public_finance_book_by_musgrave.pdf
    • http://lufevexos.atwebpages.com/alchemist_book_in_urdu_download.pdf
    • https://4900ecec-7ac1-411c-be2c-b077674085c8.filesusr.com/ugd/493135_1224749dbe02464ea66a993153b70cf1.pdf?index=true
    • http://ziwemasux.myartsonline.com/how_to_prepare_for_a_veterinary_interview.pdf
    • https://91ca87c2-c493-4616-adaa-fbcec45394e1.filesusr.com/ugd/6116da_ac082907b81d4512a8276ecc051b459e.pdf?index=true
    • https://1a413096-4115-453c-84a6-e19f3d0a1e7a.filesusr.com/ugd/4a2d03_ffac8350410a458fbbd05afad148d8bd.pdf?index=true
    • http://zisukuvi.atwebpages.com/how_to_factory_reset_plantronics_backbeat_fit.pdf
    • http://suzifoki.myartsonline.com/damotiwovukev.pdf
    • https://828c6a01-da61-4814-986a-f72e64f4f334.filesusr.com/ugd/cdfdba_f931157292b844918593634a5154265d.pdf?index=true
    • http://zujisofivo.onlinewebshop.net/25504604508.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef5f.bin
43442a056003f2144df8fb9542d368723755942a7b4df709b875586d3766d630
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF5F 5612 bytes
font_01_sfnt_off0001027d.bin
eed7f0cf1e12c37afb93813311c0918ca68dec748d7f8d5c90e0c567e5186c06
pdf-font-stream PDF embedded font (sfnt) at offset 0x1027D 11220 bytes