Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef522e08f0dc0d18…

MALICIOUS

PDF

70.4 KB Created: 2021-03-15 20:28:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 943ada6b4278a932f33bf4d0f9ab84fa SHA-1: ed8d64715d61207ecd30653e4c94bdcfa7b53575 SHA-256: ef522e08f0dc0d1875e26f18b18620ce2fdade09a72ff2335960b68e42adf481
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many of which point to potentially malicious domains, indicating a link farm or SEO poisoning tactic. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and heuristic firings point towards an attempt to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/award?keyword=chemistry+formulas+in+telugu+pdf
    • http://wukixijolori.iblogger.org/baaz_song_bhindranwale.pdf
    • http://makamar.online/bolomugukixunabukanozap0sav.pdf
    • http://onlinetiser.website/overeaters_anonymous_food_plan_gray_sheet3j5vl.pdf
    • http://mklhhhh.space/i_want_to_play_table_tennis_near_mesxj0t.pdf
    • http://xepuvibigin.22web.org/xovunexinun.pdf
    • http://nutesane.iblogger.org/90882464551.pdf
    • http://delaem-sami.online/morphology_of_african_languageszy7c6.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://2a983b51-2e13-4971-8c1f-a5bca3ab4353.filesusr.com/ugd/e1a791_94276d843c2442e6a5799356181f6230.pdf?index=true
    • https://3794eb9c-cc8b-492c-aecc-44533f76aaa6.filesusr.com/ugd/1ee69b_db7356dd41f94c1bafd9cb7bd2ea708e.pdf?index=true
    • https://s3.amazonaws.com/baxegezivumi/bhairava_south_movie_full_hd.pdf
    • https://959e49da-b405-4961-97d4-5c1bb2e9a628.filesusr.com/ugd/ab0441_ecb1626c54264d21ba20c3bf8f40e0d2.pdf?index=true
    • https://c0cead0d-5248-483d-940e-95cc3acd9bde.filesusr.com/ugd/20d83a_76b9be789e454072969fee04d2d135e9.pdf?index=true
    • https://6baea7ca-81e4-4a11-8410-716433a99462.filesusr.com/ugd/764aaa_7c12c93458514c87b53c9eba2d619332.pdf?index=true
    • https://s3.amazonaws.com/bupijila/cadastro_nacional_de_informaes_sociais_pis.pdf
    • https://e2604e0b-f95a-4acb-b53f-a7db3827b2a1.filesusr.com/ugd/225520_c14d351f395d444f93c5a1f9c79e5a44.pdf?index=true
    • https://s3.amazonaws.com/duzexefemosaxe/what_is_meant_by_an_economic_depression.pdf
    • https://944bcc21-9f45-42c2-9889-8cf837fa5d1c.filesusr.com/ugd/50f869_e5f59fe56da64597859569a64ff7364e.pdf?index=true
    • https://s3.amazonaws.com/tokatefozude/saxuwubasifepawisore.pdf
    • http://xagexof.rf.gd/28876019204.pdf
    • https://s3.amazonaws.com/murudute/ripurup.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c69a.bin
0188ee9e8443d9546e876c889a3e68a15472ef000d255ed2d28dabbb5deddc79
pdf-font-stream PDF embedded font (sfnt) at offset 0xC69A 5464 bytes
font_01_sfnt_off0000d904.bin
03d3c4de9798b9b709dec31a6fc9d9495f0783e70f596c27efb05ecc3dc8f4cf
pdf-font-stream PDF embedded font (sfnt) at offset 0xD904 3996 bytes
font_02_sfnt_off0000e7e3.bin
b67f6746f1db8977653d2634bf1d00991f66508ce2447c1ebbc49ce62b74eb5e
pdf-font-stream PDF embedded font (sfnt) at offset 0xE7E3 10844 bytes