Malicious PDF — malware analysis report

Static analysis result for SHA-256 d5b57473f767ae62…

MALICIOUS

PDF

80.6 KB Created: 2021-03-30 21:00:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5c7d937c37696a6e8164ca09b01c4255 SHA-1: da17d7b453e8c12dd48b82867b915af146ce3f00 SHA-256: d5b57473f767ae6209d2cbe1a3d671b201f17840e14ff57448983632bdaa5576
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are dynamically generated and point to other PDF documents, suggesting a link farm for SEO manipulation or phishing. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution. The embedded URLs are the primary indicators of compromise, directing users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/wix?keyword=official+act+prep+guide+2018
    • https://cdn.sqhk.co/fifenije/aia1kYO/51643141973.pdf
    • https://cdn.sqhk.co/tulazofava/dibZBWb/popular_online_computer_games_early_2000s.pdf
    • https://talunijepi.weebly.com/uploads/1/3/4/5/134599753/nibenenisisudi.pdf
    • https://cdn.sqhk.co/degamuwubela/ha4ha07/52625596930.pdf
    • https://cdn.sqhk.co/zimevegi/RQS8R9z/62914858797.pdf
    • https://cdn.sqhk.co/mapibeze/FhcMWid/toxoguselujoradifi.pdf
    • https://dirifulezidume.weebly.com/uploads/1/3/2/7/132740871/vivofalolepezaj.pdf
    • https://pufopobumosuv.weebly.com/uploads/1/3/0/7/130776602/59151b8a490.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://b0cee159-9ce3-47d2-9452-de9e383f1b6b.filesusr.com/ugd/fac5c7_9f5c0b5dcd014d239fecadd0449819af.pdf?index=true
    • https://36c7e617-1221-4173-b726-d5bce2878801.filesusr.com/ugd/610d21_44c505e5dbce415496cc6606e5603569.pdf?index=true
    • https://e4fb9bf1-a3d6-4767-9bf2-2a1021e5dc09.filesusr.com/ugd/53cfc7_1951e66889a744018324bdfd7293aa7c.pdf?index=true
    • https://uploads.strikinglycdn.com/files/e18ffb01-1cd7-46d4-a0ca-c86448df2beb/world_war_z_book_chapter_1_summary.pdf
    • https://s3.amazonaws.com/kozibowisenatu/40001634399.pdf
    • https://uploads.strikinglycdn.com/files/b479a3d3-31ac-41af-a7ac-60e8100862ae/marshall_dsl40c_with_creamback_review.pdf
    • https://s3.amazonaws.com/mokamoba/evenflo_car_seat_safety.pdf
    • https://uploads.strikinglycdn.com/files/01571ce7-b29e-4006-a57a-e22a3091f8d8/92946055886.pdf
    • https://s3.amazonaws.com/tevomenil/how_to_clear_memory_on_avh-200bt.pdf
    • https://21a67f6d-2aea-439f-a910-ed4feb6be009.filesusr.com/ugd/173616_79f2cdc5492d4b4093626f36198e71fc.pdf?index=true
    • https://s3.amazonaws.com/nisoxow/how_much_weight_should_i_lose_monthly_after_gastric_sleeve.pdf
    • https://uploads.strikinglycdn.com/files/40eb1620-075c-4db8-adde-c5eb57e95145/how_does_an_investigator_prepare_for_an_interview_or_interrogation.pdf
    • https://uploads.strikinglycdn.com/files/f4224b79-670e-4ac2-a030-cbb8152106be/speed_queen_repair_videos.pdf
    • https://74df6fe0-557b-4e47-8461-f2df536053d0.filesusr.com/ugd/4dcf4e_4ffe19d49d7e48cbb869e83df4771be8.pdf?index=true
    • https://s3.amazonaws.com/xofalepelala/gst_tax_slab_item_wise.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fa6f.bin
c72e59273519b4c643651a2358767e5acb818cf4d5a0748157b921c376a513ab
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA6F 5692 bytes
font_01_sfnt_off00010dea.bin
0d8f940af1156214847349404bbf482cb1f7adffcd8ac60037a6ae59b8cf23e2
pdf-font-stream PDF embedded font (sfnt) at offset 0x10DEA 11044 bytes