Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5f1faa7dc393168…

MALICIOUS

PDF

96.3 KB Created: 2021-03-23 19:15:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 07919dc75b1296010c1678205fdf3362 SHA-1: 16de660576ac2fd580f049a9c3115edba0713cae SHA-256: e5f1faa7dc3931684b99e455d175581df014e3410fbccfb2a2c5e3f6b601f997
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was identified as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains a large number of external links, many of which point to other PDF files, suggesting a link farm or SEO abuse tactic. One of the embedded URIs, 'https://crophysi.ru/wix?keyword=how+to+summon+the+grim+reaper', indicates a potential lure, while the heuristic 'PDF_SEO_LINK_FARM' confirms the presence of numerous external links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/wix?keyword=how+to+summon+the+grim+reaper
    • http://recepty-dd.info/xuvagol3lb.pdf
    • https://xovobinawulum.weebly.com/uploads/1/3/4/8/134883327/8059478.pdf
    • http://daating19.site/hd_wallpapers_for_iphone_6_1080p_animegsxfv.pdf
    • http://jakebaxujimug.22web.org/emotional_abuse_in_marriage.pdf
    • http://copyright-services-us.com/how_many_quarts_of_transmission_fluid_does_a_2005_gmc_envoy_takefdrsl.pdf
    • https://xuporavima.weebly.com/uploads/1/3/4/3/134363981/pulajewizotalaf.pdf
    • http://kinoogf.space/review_naming_ionic_compounds_answer_keyx22ta.pdf
    • http://uchebnoe.website/32482001200b8smr.pdf
    • http://heleogose.online/duvipojymle.pdf
    • https://bokasopuvozanib.weebly.com/uploads/1/3/4/3/134319525/9b4e5045658347b.pdf
    • https://pijaremurepapo.weebly.com/uploads/1/3/1/4/131406688/1670434.pdf
    • http://pevojatinolotej.22web.org/42962031090.pdf
    • https://lumejukotexute.weebly.com/uploads/1/3/1/1/131163930/padokonen.pdf
    • http://idslim-italia.site/bugera_v22_infinium_guitar_combocwcyi.pdf
    • http://goodsun.space/my_little_scythe_downloadodqgh.pdf
    • http://reduslimitalia-official.site/mibaxosidibewosusesf82.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://puzugewowe.epizy.com/88364675486.pdf
    • http://pususarejopo.epizy.com/destination_a1_a2.pdf
    • https://bb0106b8-f3e0-414b-a873-a0e24df3f2ad.filesusr.com/ugd/b84a33_8c7f0d42939647e6aee3b8988a1b74b7.pdf?index=true
    • https://d992f69e-bc5b-430a-92d7-abfd66d0380b.filesusr.com/ugd/6f7357_a4cc24fc90f849cebf43e388da233548.pdf?index=true
    • https://76c9fb28-c10e-4950-85be-37de24a2ede8.filesusr.com/ugd/fa32a6_dc8a1bd200734c96a9aecab5289570d7.pdf?index=true
    • https://a19d597f-2220-41b3-9459-688249e8a20b.filesusr.com/ugd/f19f53_300e18ca206048aeb5b82f412d8b844b.pdf?index=true
    • https://18cceff7-6d50-42ec-9d85-67184b61345e.filesusr.com/ugd/8c2e83_a3e09111f29047248db3fb06fe44f722.pdf?index=true
    • http://galopaxuvubopuj.rf.gd/apostila_noes_de_administrao_pblica_para_concurso.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00013962.bin
a2638c745d8d469c5ab5fa1ef754b26bd00bd1447c34ef2d924c9ca76b1b1d25
pdf-font-stream PDF embedded font (sfnt) at offset 0x13962 5256 bytes
font_01_sfnt_off00014b2b.bin
88323cf202bdfab9bc0919079751541c726e7f6074651f52ae49316459bae5ae
pdf-font-stream PDF embedded font (sfnt) at offset 0x14B2B 12284 bytes