Malicious PDF — malware analysis report

Static analysis result for SHA-256 d5093e53c7f2feb2…

MALICIOUS

PDF

80.5 KB Created: 2021-03-22 06:54:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 97981edbe4f9cae7aa86007fd0119add SHA-1: e9cdf932de09bd0f8a57fd43a31f132522ac0da5 SHA-256: d5093e53c7f2feb2857924f45b4373d1f261047346d5cb2397f1a1b9a44999cf
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which point to other PDF documents, indicating a link farm or SEO spamming attempt. The ClamAV detection and ML classifier strongly suggest malicious intent, likely phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=health+economics+graduate+jobs
    • https://cdn-cms.f-static.net/uploads/4406464/normal_60452fe0a0b40.pdf
    • https://cdn.sqhk.co/pegatorapo/AvihA5z/42571657290.pdf
    • https://cdn.sqhk.co/giwumazusew/wiajjge/jadarunamegumuris.pdf
    • https://cdn-cms.f-static.net/uploads/4417986/normal_5fda4b3d141d1.pdf
    • http://dazavaluk.mygamesonline.org/assertiveness_books.pdf
    • https://cdn.sqhk.co/fugutexifi/4chghjp/hallmark_movie_list_christmas_2019.pdf
    • https://cdn.sqhk.co/busumodofu/ijg1TLJ/international_business_management_best_universities_uk.pdf
    • https://cdn.sqhk.co/doparibi/YShjHRI/95768967207.pdf
    • https://cdn.sqhk.co/gikunixa/ifhehjf/32399638670.pdf
    • https://cdn.sqhk.co/pakelabete/FgdYggR/pebubuzax.pdf
    • http://medebupima.sportsontheweb.net/auscultation_of_heart_sounds.pdf
    • http://dotixomovi.sportsontheweb.net/bobina_automotriz.pdf
    • https://cdn.sqhk.co/jasurisunav/bCjdhdi/44777788533.pdf
    • https://cdn.sqhk.co/zekafomaze/ii2DfSg/rimisaxabuzataferipatide.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://95a83a18-022f-4aa5-9dc2-588eac4c5c4a.filesusr.com/ugd/ccb6ab_8d193bffa19c43bda0629066bfd6b3ff.pdf?index=true
    • https://434dcbc4-7bd9-40fe-99bf-e102daebf961.filesusr.com/ugd/07ef24_7485d4453a094862a4eef1d5c3797650.pdf?index=true
    • https://5e446c31-fcb6-4427-a178-91ee45bbff8b.filesusr.com/ugd/4e76b8_de2ae19595b0476087ddcf40c62ec60e.pdf?index=true
    • https://044e8d80-c429-4a1f-820d-9b443c65b389.filesusr.com/ugd/53c654_ad3675aec1b24c5e9eca007fa2d88182.pdf?index=true
    • https://5e73d190-47a4-4ead-99bf-7e9069f06a16.filesusr.com/ugd/55cc32_5d1ffbae3ba64e448df0279450ca4a7d.pdf?index=true
    • http://fararisujis.myartsonline.com/20000_leagues_under_the_sea_chapter_12_summary.pdf
    • https://b03e51a8-7171-48c0-94d6-e4c032e6f37f.filesusr.com/ugd/9421c8_d6dbf1c81acb4e8dae0cdd269dfaa57b.pdf?index=true
    • https://b3dfd9c9-1030-471f-a26d-814ea73dbccc.filesusr.com/ugd/d97afa_226e544de68c442e92f60e2878e84eac.pdf?index=true
    • https://684917c6-b594-4497-9ea4-141105166a5b.filesusr.com/ugd/0dc9f5_d5d98a587b184cf9b0bfc46dce046b25.pdf?index=true
    • https://8ed62699-7d02-4439-b935-4286882ef7d4.filesusr.com/ugd/229b11_a3776a00a8f64e85a4cefb8d802f878f.pdf?index=true
    • https://681956c7-2c57-495f-b996-d04b50c745b0.filesusr.com/ugd/907d98_8606c595a1814bb5aa6524e2d2391f52.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb8a.bin
a690ba1f4bd8ad7622e8f42ed47c45ba6c3245ccd3fcc29e8b893d52621660af
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB8A 5412 bytes
font_01_sfnt_off0000fdb1.bin
c76bf10d433d3ed65082d0358e7748811da00afcd05affeaf6e925ff42e28e7b
pdf-font-stream PDF embedded font (sfnt) at offset 0xFDB1 11508 bytes
font_02_sfnt_off000124c1.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x124C1 4324 bytes