Malicious PDF — malware analysis report

Static analysis result for SHA-256 edb52d823ee6e146…

MALICIOUS

PDF

73.6 KB Created: 2021-04-05 19:08:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1897b9ea13999118ff2503caf733ae40 SHA-1: 10ee0f3981da34357f1dc45b576ea9d18561d0a9 SHA-256: edb52d823ee6e146d0cc6ca82526cbec34ec79507de601723933048f60c3a534
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, indicating malicious intent. It contains a large number of external links, many pointing to S3 buckets with numeric slugs, suggesting a link farm or SEO poisoning tactic. One prominent external URI, https://jacksth.ru/award?keyword=5+steps+of+grievance+procedure+pdf, is likely the primary lure, attempting to trick users into believing it's a legitimate document. While no scripts were explicitly extracted, the PDF structure and the nature of the heuristics suggest it may exploit PDF vulnerabilities or embed malicious JavaScript to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8115

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/award?keyword=5+steps+of+grievance+procedure+pdf
    • https://cdn.sqhk.co/ridijafugemi/fgfXjdi/alarm_clock_no_sound_iphone.pdf
    • https://cdn.sqhk.co/bujutinape/Vnhb5Ll/lezunepeken.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/tapelu/57668639448.pdf
    • https://s3.amazonaws.com/pidufozu/incident_report_format_fire.pdf
    • https://s3.amazonaws.com/pajukovuxetu/ethnicity_choices_on_forms.pdf
    • https://s3.amazonaws.com/napoledunadigo/cen_tech_multimeter_battery_test.pdf
    • https://s3.amazonaws.com/bokexizometun/nagepof.pdf
    • https://s3.amazonaws.com/remavuj/project_almanac_full_movie_480p.pdf
    • https://4454cc88-256b-48ad-9013-c0414c72072d.filesusr.com/ugd/67e251_df18434dc8b14b2fa8753cdf8fab67c8.pdf?index=true
    • https://s3.amazonaws.com/xafaxotaful/53099195263.pdf
    • https://s3.amazonaws.com/nitidadufetenu/busurenezofuzudubaz.pdf
    • https://s3.amazonaws.com/befarekogol/politique_dfinition.pdf
    • https://s3.amazonaws.com/bokofapig/50625809322.pdf
    • https://s3.amazonaws.com/kabisebax/star_format_interview_questions_and_answers_examples.pdf
    • https://s3.amazonaws.com/sojaxub/81884070032.pdf
    • https://s3.amazonaws.com/mubemutolewe/60355872169.pdf
    • https://f4dd034e-00c7-465c-b850-fb2d75accad5.filesusr.com/ugd/769f78_4e11a643f12640959b2d03b868412d0f.pdf?index=true
    • https://584abdf6-e408-48d3-a53c-4313a8f82471.filesusr.com/ugd/18ee90_1436effc64d244ec94351ba21cfa0cde.pdf?index=true
    • https://s3.amazonaws.com/viboxikuz/how_to_use_hunter_xcore_sprinkler_system.pdf
    • https://s3.amazonaws.com/nabifovu/maviwufuzi.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e260.bin
779586a371314529c9422d43f58e3a769398fed9a4166bc3135145a51136e3db
pdf-font-stream PDF embedded font (sfnt) at offset 0xE260 5380 bytes
font_01_sfnt_off0000f4c7.bin
d147a7d1c92b89c3fde92c2ab50a8c13d34e572001a01a0d78c3520901c75404
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4C7 10596 bytes