Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8c9aa9f4a4b52ca…

MALICIOUS

PDF

78.5 KB Created: 2021-05-25 13:45:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fac9a0a6a2ef56daccd68ebce3dc8680 SHA-1: d59acad6f510b6029162df694df51c533ed1b728 SHA-256: d8c9aa9f4a4b52ca8093cdc89b6362001b7f83630a4a29d621d765c14cf5be21
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to other PDFs, suggesting a link farm or SEO abuse for malicious purposes. ClamAV and ML classifiers indicate malicious content, specifically identified as Pdf.Phishing.Trojan. The embedded links likely lead to malicious sites or further payloads, indicating a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/strik?utm_term=definite+indefinite+and+partitive+articles+in+french+exercises
    • https://static.s123-cdn-static.com/uploads/4420260/normal_60055e433f3ce.pdf
    • https://cdn-cms.f-static.net/uploads/4486045/normal_6038dfe28057c.pdf
    • https://cdn-cms.f-static.net/uploads/4446166/normal_602f46c781c27.pdf
    • https://static.s123-cdn-static.com/uploads/4377938/normal_60047a2a21fb4.pdf
    • https://cdn-cms.f-static.net/uploads/4454170/normal_600b24070a068.pdf
    • https://kuwuxezito.weebly.com/uploads/1/3/6/0/136090431/fifez_milopapiwide.pdf
    • https://cdn-cms.f-static.net/uploads/4478402/normal_5fdc5ab3effba.pdf
    • https://static.s123-cdn-static.com/uploads/4488804/normal_5fe2567851258.pdf
    • https://cdn-cms.f-static.net/uploads/4481420/normal_603d22ffab593.pdf
    • https://static.s123-cdn-static.com/uploads/4384650/normal_5fd060253ba43.pdf
    • https://cdn-cms.f-static.net/uploads/4450138/normal_603d08fd6aa1a.pdf
    • https://static.s123-cdn-static.com/uploads/4413976/normal_5fcb6477e5ae8.pdf
    • https://static.s123-cdn-static.com/uploads/4409103/normal_5fed6a6c1aff9.pdf
    • https://nakakikixug.weebly.com/uploads/1/3/4/4/134490848/d188bbc270.pdf
    • https://refapezi.weebly.com/uploads/1/3/4/9/134904673/f66f2e918bbb91a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/1cf936dc-5758-46d6-8465-de7dfaf596d7/jexixovegetedela.pdf
    • https://uploads.strikinglycdn.com/files/7e5a5b0d-23ca-44ac-b7b5-dfd490cf14b7/what_is_literature_meaning.pdf
    • https://uploads.strikinglycdn.com/files/204165f8-be82-443b-9b60-aa4b0f1a0098/how_to_write_an_expository_essay_7th_grade.pdf
    • https://uploads.strikinglycdn.com/files/c01c41eb-3b83-4131-bcef-78313faa17de/4691790764.pdf
    • https://uploads.strikinglycdn.com/files/ce681931-6e7f-4d40-8478-882eea213f76/wafefakarasidi.pdf
    • https://uploads.strikinglycdn.com/files/2424aa06-453e-4b46-abff-bb3eba2792ad/suzuki_sidekick_lift_kit.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f112.bin
caab3930c0aa5e316b65b6205d182bccfc9afb0a960ec8ab388a4faca9fa064b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF112 5368 bytes
font_01_sfnt_off00010364.bin
57ade25cfba07defa03d32a5f5dec3ba0d476eb190ab85ae8e50a04b6dec31c9
pdf-font-stream PDF embedded font (sfnt) at offset 0x10364 11984 bytes