Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0ab108d99b8d90f…

MALICIOUS

PDF

66.8 KB Created: 2021-03-25 04:51:32 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f40eeab1454f1ef926496d4a674a8a38 SHA-1: cfc6a08a71e77421ffff5f9691860569250e6681 SHA-256: c0ab108d99b8d90fa6ef5a42c24e78ce2a009e715a0fea278df1f3a665ea6503
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics as malicious, including a critical finding for a PDF link farm. It contains numerous external URIs, with the primary malicious indicator being the link to 'https://crophysi.ru/award?keyword=genetic+counselling+book+pdf'. While no scripts were explicitly extracted, the PDF structure and the presence of external links suggest an attempt to redirect users to potentially harmful content, aligning with phishing or SEO manipulation tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7994

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/award?keyword=genetic+counselling+book+pdf
    • http://nufivuzelikonax.getenjoyment.net/jolibute.pdf
    • http://potawuzaj.medianewsonline.com/cub_cadet_model_2166_owners_manual.pdf
    • http://tafiwon.mywebcommunity.org/kadakobofunorep.pdf
    • http://pigalimiru.medianewsonline.com/mifamuwaberewitasafugelu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zudupaxub.myartsonline.com/society_bye_laws_2020_in_marathi.pdf
    • https://uploads.strikinglycdn.com/files/a9ac74a9-9cbe-4106-afa3-b920e3e1a763/guitar_theory_for_dummies_review.pdf
    • https://uploads.strikinglycdn.com/files/348a0342-cb2c-4346-8f21-e775fb9262f9/best_esl_grammar_workbooks.pdf
    • https://uploads.strikinglycdn.com/files/3157a9bb-d54a-4654-b062-c406008de4c4/what_is_a_customer_service_strategy.pdf
    • https://uploads.strikinglycdn.com/files/f8f8c4a4-f51e-4f37-88a0-7d44dcf4636c/environmental_impact_assessment_process_slideshare.pdf
    • https://s3.amazonaws.com/laginekux/pdf_auditing_2.pdf
    • https://uploads.strikinglycdn.com/files/3b869fb9-845b-400e-bc06-7568f6fa1e2c/metujezewebokibenekamag.pdf
    • https://83372c7a-1065-4b07-8284-b64562b46e84.filesusr.com/ugd/035489_2669fe9ceab74cde85994d3de381707f.pdf?index=true
    • https://s3.amazonaws.com/wixamupelinere/analog_clock_worksheets_for_kindergarten.pdf
    • https://s3.amazonaws.com/lurutopobi/electrical_estimation_and_costing_vtu_notes.pdf
    • https://uploads.strikinglycdn.com/files/5396536c-7909-4661-8232-cd49b88ebf25/sagigimugunawigijifut.pdf
    • https://uploads.strikinglycdn.com/files/82f2f077-0a83-4930-abd9-6a87e3b06c4a/binebakobaxatilajenom.pdf
    • http://revudipepofaten.myartsonline.com/48104252864.pdf
    • https://s3.amazonaws.com/widofafane/how_to_program_wayne_dalton_quantum_garage_door_opener.pdf
    • https://uploads.strikinglycdn.com/files/c2a1c336-3687-4021-be5a-0a6880499969/lenovo_thinkpad_t430_review_2018.pdf
    • https://4b523d79-2bc6-404f-8e52-0acae4d2cb03.filesusr.com/ugd/fe1b41_7b0fb879d3284574a795627ede340a3d.pdf?index=true
    • https://s3.amazonaws.com/mejifavo/89573590768.pdf
    • https://uploads.strikinglycdn.com/files/5a15912c-6928-4587-9d5e-5c6e5f6edfed/resijo.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e32b.bin
74398c7051ba67b643af0b5bf4c54016c142ebf4f5f863f1108859e6505115e0
pdf-font-stream PDF embedded font (sfnt) at offset 0xE32B 5252 bytes