Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc5252b4d211413b…

MALICIOUS

PDF

82.9 KB Created: 2021-03-21 00:12:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 015eb3829e78bce36be9743824f50b5a SHA-1: 25959d64d26580da3524b0195563d1a40342908b SHA-256: cc5252b4d211413beff502e267be7bfb745e45d556c0cf2f99e365ea2f4a0201
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which are dynamically generated and point to potentially malicious domains, indicating a link farm or phishing attempt. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a malicious document designed to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=sunmica+door+design+catalogue+pdf
    • http://rakajipof.22web.org/bypass_proxy_android_mobile.pdf
    • https://static.s123-cdn-static.com/uploads/4383692/normal_6008fd2b642e2.pdf
    • https://static.s123-cdn-static.com/uploads/4369774/normal_5ff9c07646751.pdf
    • https://cdn-cms.f-static.net/uploads/4387709/normal_6019509e77275.pdf
    • https://cdn-cms.f-static.net/uploads/4372373/normal_5fea272602589.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://07bd7893-a6ec-44d5-90fe-c719e602c0bd.filesusr.com/ugd/aafaff_e78f771095e6463dae8fefc1f6f87073.pdf?index=true
    • http://fawexoja.rf.gd/vimipajuxiduzadomero.pdf
    • https://s3.amazonaws.com/vizegemawokaxe/aggiornamento_android_10_q.pdf
    • http://lolofekigosot.epizy.com/how_to_draw_a_simple_anime_face.pdf
    • https://s3.amazonaws.com/vuforewebub/95447617958.pdf
    • https://9e2b3e3a-6a02-4d3b-8ba9-5acc01041672.filesusr.com/ugd/66c878_8ba8dcd8763e4d3fadc63c0293f61c28.pdf?index=true
    • https://s3.amazonaws.com/nevowimo/how_to_use_volume_indicator_in_tradingview.pdf
    • https://s3.amazonaws.com/luxaduzimase/rewuvozabebatudokoru.pdf
    • https://ad217471-f301-4d07-b05b-71cdb813ff8b.filesusr.com/ugd/4f915f_d26f301777084389b902478c415f1e73.pdf?index=true
    • https://s3.amazonaws.com/kodipopujufipig/45454142506.pdf
    • https://s3.amazonaws.com/zebarufuridorur/50299478803.pdf
    • https://s3.amazonaws.com/vedexajawo/android_studio_how_to_install_ndk.pdf
    • https://e5720c39-3c1c-4a52-9be9-509675281b5a.filesusr.com/ugd/0010c8_d4b7cac2623b4d6481e149ddf6f4e0c1.pdf?index=true
    • https://s3.amazonaws.com/vifusupegiza/tadaxobavifofokori.pdf
    • https://s3.amazonaws.com/legipalofi/way_back_home_song_pagalworld.pdf
    • http://jilerixam.epizy.com/61209154568.pdf
    • http://nuzebavin.epizy.com/a_clockwork_orange_slang_guide.pdf
    • https://s3.amazonaws.com/robumuduluwise/23830834130.pdf
    • https://104e0e48-a4c2-4a03-8647-06ef64d4e6ac.filesusr.com/ugd/e2c6c1_b3fe6668d61f4e1795c6160e825f4b37.pdf?index=true
    • https://s3.amazonaws.com/pizivurapab/57011470839.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000109bf.bin
ced17671c1e51191b41c92b2b0733860b92c93d58d3e03ffcf75cdbfdd9f8f86
pdf-font-stream PDF embedded font (sfnt) at offset 0x109BF 5580 bytes
font_01_sfnt_off00011c9e.bin
8b52c66b48760c4252b313a8983ab2bfa766bece17719c1003e8945180ea6827
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C9E 9700 bytes