Malicious PDF — malware analysis report

Static analysis result for SHA-256 decbca47b1736568…

MALICIOUS

PDF

71.9 KB Created: 2021-05-19 13:00:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-16
MD5: ace903d137e9b79b7b3a9d297ccefe76 SHA-1: 475cc6e9ba92c1937ec524bd0d3e3f6ecc1630e6 SHA-256: decbca47b173656895e1721fb53e4f954ec32d69f2bc836285f9dced307573c1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was identified as malicious by a machine learning classifier and ClamAV, with critical heuristics indicating a link farm and external URI usage. The document body, though partially corrupted, suggests a lure related to Spanish verb conjugation exercises. The presence of numerous external links, including one to 'jacksth.ru', indicates a likely attempt to manipulate search engine results or redirect users to malicious sites, consistent with phishing or SEO spam tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=ejercicios+conjugaci%25C3%25B3n+de+verbos+en+espa%25C3%25B1ol+pdf PDF link annotation
    • https://faniwavuguvupos.weebly.com/uploads/1/3/4/4/134478403/6617085.pdfIn PDF document text
    • https://nirodafudo.weebly.com/uploads/1/3/4/6/134697392/97de69f1e.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/wazorixekunafob/apa_reporting_hierarchical_regression_results.pdfIn PDF document text
    • https://s3.amazonaws.com/gowupuzokowuxes/90035091928.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/40115c32-3a99-42bf-ad92-8d73dbcb4a56/famabixebin.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ba352d27-c528-471c-94b3-e7be33390e99/john_deere_ride_on_mower_seat_cover_nz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ba81b8eb-117e-4fba-93f6-125a471c134d/pusoveliloguxifokevix.pdfIn PDF document text
    • https://s3.amazonaws.com/sojebelevenex/apics_cscp_learning_system_2017.pdfIn PDF document text
    • https://s3.amazonaws.com/gedesisumi/user_acceptance_testing_format.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/42838f6b-bd3a-4fc8-a63a-7e7ba0b4e95b/56968620660.pdfIn PDF document text
    • https://s3.amazonaws.com/zazelujeju/single_cycle_vs_multi_cycle.pdfIn PDF document text
    • https://s3.amazonaws.com/sisaxu/digital_marketing_concepts.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1f89e4a7-7e42-4572-90b4-c53e99609704/xemedalovapasi.pdfIn PDF document text
    • https://s3.amazonaws.com/tobaziw/payment_agreement_form_for_irs.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8ccfc24b-5cc7-49fa-8b1a-12e7029283f7/44639586601.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/546b7f52-d0c4-4602-8064-d3d0bb7db26f/how_does_sump_pump_float_switch_work.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3f8b2f67-2397-4bdf-b171-d4b0a02f7ea1/xirikedopiniwitajewoferit.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e5357674-4f1a-482c-90de-44e260bd5837/star_wars_knights_of_the_old_republic_2_timeline.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d826.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD826 5904 bytes
SHA-256: 7e6c6af5bc1da6893f86ef7c2decacf5ddcbbc9565421ae79b0d79230990afc6
font_01_sfnt_off0000ebe0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEBE0 10896 bytes
SHA-256: 74ef29f32fcff686d70c561430621b0b987d625779afb927d6a46c3209431ce2