Malicious PDF — malware analysis report

Static analysis result for SHA-256 d19276abfba024ef…

MALICIOUS

PDF

78.0 KB Created: 2021-03-11 18:00:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 809ba1fb244f5eec9e29103699e4a687 SHA-1: d4db334029ea6abea13f2e1ec5679c5b06fa5ffe SHA-256: d19276abfba024ef0fa0bf826e7b4c1d73eea4f55c4a150d7318db0c897af830
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a critical heuristic indicating a link farm designed for SEO manipulation. One of the primary links points to a URL that appears to be a lure for accounting and finance MCQs, suggesting a phishing or malware distribution attempt. The ClamAV detection and ML classifier further support the malicious nature of the file, likely serving as a dropper for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/award?keyword=accounting+and+finance+mcqs+pdf
    • http://alcexpress1.xyz/95093684859pd9ft.pdf
    • http://gutowofobujibos.iblogger.org/66281439595.pdf
    • http://kobujiva.iblogger.org/it_program_manager_interview_questions_and_answers.pdf
    • https://zeberafuduzugag.weebly.com/uploads/1/3/2/6/132682167/motewumobif.pdf
    • http://idealica-italy.site/kung_fu_panda_3_full_movie_in_hindi_download_filmymeet6tpmy.pdf
    • https://zogugixuwomu.weebly.com/uploads/1/3/4/2/134234599/6147002.pdf
    • https://jaregufadux.weebly.com/uploads/1/3/4/0/134016720/fijumuno-niberik-moxojif-zewofeme.pdf
    • http://kvrovk.xyz/scroll_saw_3d_patterns_freekvrao.pdf
    • http://bloomwithdeanna.com/blomberg_dishwasher_e16963h.pdf
    • https://menekagamop.weebly.com/uploads/1/3/4/0/134097565/b029cc3161.pdf
    • http://expressvpn.store/508051805253zvit.pdf
    • http://easy-money-cash.space/wadebotakitiviwiwtnkr0.pdf
    • https://belatefa.weebly.com/uploads/1/3/0/7/130775380/d80b352859a493.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://e966359d-176b-477a-9ad9-c314bea94227.filesusr.com/ugd/fa6f14_8ade3b463a68483eb42b56568da89732.pdf?index=true
    • https://3b87a2b8-2d13-4e6d-acc4-cbba57692a59.filesusr.com/ugd/50988c_97d4ea47876943ef8f9d6849516be263.pdf?index=true
    • https://1f49b3f1-4b09-4f89-88df-03804352fc9a.filesusr.com/ugd/a51aec_b5d25afd973c4f03981a47c862ebe020.pdf?index=true
    • https://f421159b-d329-41e8-bc42-072bc93e4c50.filesusr.com/ugd/65d6f7_3dbabc34d9ae463b99d5a2cdd9d51e11.pdf?index=true
    • http://veboxin.epizy.com/dediwudas.pdf
    • https://564fd4a8-0e6d-4f97-813a-a14a70c45316.filesusr.com/ugd/f90d28_f0d0ec9c2d9b4d248972560b805ebf0b.pdf?index=true
    • https://f3874c2d-c116-49c2-b7b6-9300dc8fc43e.filesusr.com/ugd/b11f6d_d4cf600766184f7b96003131988c7031.pdf?index=true
    • https://2dcb0092-dd22-4cef-90c1-8c398f802bb7.filesusr.com/ugd/ff3115_e7fd67bbe75d41919cc78e35867f189f.pdf?index=true
    • https://7afd96e6-4611-46d4-9b98-d111b897c281.filesusr.com/ugd/154221_4f453a0371734a7cac7ebc9a98f09dc4.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f259.bin
58cc8c613cfab2bd366a08ade150c5c66722a9da913f02f91aa3ce8ecbdfb866
pdf-font-stream PDF embedded font (sfnt) at offset 0xF259 5460 bytes
font_01_sfnt_off000104df.bin
b3151e3b601a0e3e0aab559a555021526da232b78d1eb4e1f571517a79cb721f
pdf-font-stream PDF embedded font (sfnt) at offset 0x104DF 11412 bytes