Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0565075112d5705…

MALICIOUS

PDF

147.1 KB Created: 2021-04-04 17:39:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 9c8a96747d9e7ef3d161ed74a079f65d SHA-1: d19923df7413b517df574a1d142d265281e4b5c3 SHA-256: d0565075112d570509a776e18ad8557df19df6641ef69188b19cc65099f2f2df
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/123?utm_term=grade+9+english+curriculum+guide PDF link annotation
    • https://wasexakenisopi.weebly.com/uploads/1/3/5/9/135982815/6983114.pdfIn PDF document text
    • https://zukixuvaxetili.weebly.com/uploads/1/3/5/9/135988851/fududisupisiwap-fekewidefikozi.pdfIn PDF document text
    • https://forexegazujolo.weebly.com/uploads/1/3/4/1/134108883/biganebeluluzapemi.pdfIn PDF document text
    • https://xibuderopugef.weebly.com/uploads/1/3/4/0/134042602/971d14f5826066.pdfIn PDF document text
    • https://jaluzirilunotu.weebly.com/uploads/1/3/2/6/132681851/jirikimavizebifif.pdfIn PDF document text
    • https://tonuwuro.weebly.com/uploads/1/3/0/7/130739505/6881155.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://b416d2a3-330e-4518-8f5e-c931256b4cd1.filesusr.com/ugd/5168b2_9417119016ff4fbf8f72844e1462b34f.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/19156565-38f3-42a9-8792-b8d8edd94b24/determine_the_kinds_of_intermolecular_forces_that_are_present_in_so2.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/38681f17-7c46-499a-9ea3-5d8fa2966f3d/rokiloje.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3821e76e-6c97-439c-af08-6222303243ec/what_is_meant_by_statistics_in_english.pdfIn PDF document text
    • https://eb62986f-0112-409a-9ebe-777412bc5c19.filesusr.com/ugd/26938b_03d201384be548f08520937f9c61efb5.pdf?index=trueIn PDF document text
    • https://a179b4bb-f9e1-4b0b-8685-f881d2afde68.filesusr.com/ugd/0fdb6d_17c1819f5be54edeaab5b42fcb74fef5.pdf?index=trueIn PDF document text
    • https://4a0f17ac-6ce6-4c05-9546-25c48d39d9f7.filesusr.com/ugd/cd79e3_91e3568870764dd4910ad1d4accb2b69.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/1cb163f9-c412-4c3d-aff2-de3d73b93a46/what_is_the_meaning_of_chemical_kinetics.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/76c18e49-3bb8-4901-a1d8-a054c889479a/jazz_2nd_edition_by_scott_deveaux_and_gary_giddins.pdfIn PDF document text
    • https://71a0d42b-91d5-4e94-9338-ff69ca8a624b.filesusr.com/ugd/e5d5e5_38ff10c595fd46f7810ed4d9e7fd367c.pdf?index=trueIn PDF document text
    • https://d03ec42c-8b93-48d3-a61e-9aee396c0db4.filesusr.com/ugd/1e557c_171bfdeefcdc48cca4ba31b209c51272.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/dd65527a-31d5-4aa8-93c0-8e7280d41bbf/star_wars_edge_of_the_empire_books.pdfIn PDF document text
    • https://b54663a3-ff9d-4122-b75c-69b71428c9b0.filesusr.com/ugd/cfa91a_5a166212a76b46a2ac26eb5303aba6fe.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/781ced11-628e-47b4-b698-3c0287d68170/lincolns_plan_for_reconstruction_in_the_south_was_known_as_the.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9c31bb6b-15be-4eca-a086-45ddec997311/what_kind_of_habitat_does_a_komodo_dragon_live_in.pdfIn PDF document text
    • https://c8f6a2ed-bc8a-4fd4-b26a-19707db7c4cd.filesusr.com/ugd/1cc7e8_3f274cb2125d4bc389594e92a7b5f8b1.pdf?index=trueIn PDF document text
    • https://0aed7b51-d02b-4864-a6bb-b478bb809667.filesusr.com/ugd/fbdaab_53fed89e2fc240c6837f5cf6c2c15737.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/7d48e4b9-4bc5-4419-936a-d5fddf103f62/intellicharger_i2_blinking_yellow_light.pdfIn PDF document text
    • https://d7e981a8-8c4a-445e-aef0-60d3d4911bd2.filesusr.com/ugd/65d69c_e5ead54072ab4622ac60de02df389401.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000205d4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x205D4 5540 bytes
SHA-256: d7376412ed537f89b4439f0c9b8a6de9ad8ab1b64bcff911a6e24ca2bdf3e877
font_01_sfnt_off00021880.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x21880 11096 bytes
SHA-256: 76a6ecaf812d3103198c52139fc5f92799a7a92655e2151595e8a9c9faa6ba16