Malicious PDF — malware analysis report

Static analysis result for SHA-256 e509420c03c42436…

MALICIOUS

PDF

77.8 KB Created: 2021-05-11 05:17:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 92642102242d627c1bff2b9a84e66f60 SHA-1: 68ed3d440b37940ae814171467200035b4884a37 SHA-256: e509420c03c42436846d59bb41382650056a2e06bc69fa28f4b0b7be0d4a2db2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are dynamically generated and point to other PDFs, indicating a link farm or SEO spamming operation. One of the primary external URIs, https://nipisod.ru/strik?utm_term=text+oh+danny+boy+karaoke, is likely a malicious redirection or phishing site. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=text+oh+danny+boy+karaoke
    • https://cdn.sqhk.co/vasegodesazu/ehg4jfC/mosufepapovepagurej.pdf
    • https://cdn.sqhk.co/juzilolawu/YgiLmgy/guputadukonagu.pdf
    • https://kanumipiga.weebly.com/uploads/1/3/5/3/135346224/juxawes_vomiketagid_jonotojin.pdf
    • https://cdn.sqhk.co/fomiroza/jhbiaii/lenovo_moto_smart_assistant_app.pdf
    • https://fawurefo.weebly.com/uploads/1/3/4/4/134441885/5188146.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/151ece44-28f5-492d-9952-c1fe2c28f606/ditepixazuluvukokorakat.pdf
    • https://uploads.strikinglycdn.com/files/df345ac0-ffae-43ad-b6bc-796c7157ef29/4375489233.pdf
    • https://b7e73dfe-ad35-4791-b4f7-7500f5b7882c.filesusr.com/ugd/bc79a4_8ef2c07cb1a24fb18dc0cb4e73710689.pdf?index=true
    • https://s3.amazonaws.com/gelawiweza/89221076071.pdf
    • https://uploads.strikinglycdn.com/files/ae23033f-f173-4b91-a12f-c8f95e021c34/english_second_language_lessons_online_free.pdf
    • https://s3.amazonaws.com/kosipefojaw/35429368412.pdf
    • https://uploads.strikinglycdn.com/files/26f3bbab-c898-4469-af64-7ba5b335dc14/kojitivan.pdf
    • http://didojolo.rf.gd/100_antonyms_words.pdf
    • http://dawubiri.rf.gd/english_grammar_basic_test.pdf
    • https://uploads.strikinglycdn.com/files/15e7e0f9-f071-459d-b7f5-318ae5b0c3b9/bushnell_northstar_goto_telescope_manual.pdf
    • http://jasixerebav.epizy.com/piridorijadipi.pdf
    • https://s3.amazonaws.com/xotomisen/what_not_to_eat_when_doing_a_candida_cleanse.pdf
    • http://kajemirari.rf.gd/sizoxarojafuserojididovo.pdf
    • https://e321b6f2-2a0a-4c58-8c60-26baf46d82f1.filesusr.com/ugd/14900c_a63e513bdc0241c8b9195378509c6cec.pdf?index=true
    • https://s3.amazonaws.com/kubedukowug/grade_12_analytical_geometry_questions.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eed2.bin
26dd6b19c5bcebda105ad8c75b95e0ec28a37a887848d6468bc3428798d968af
pdf-font-stream PDF embedded font (sfnt) at offset 0xEED2 5028 bytes
font_01_sfnt_off0000ffed.bin
6d9e7b36e01a0bac230156552c95fa410e7a2e57a1e41c32f529f852907fcc89
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFED 13460 bytes