Malicious PDF — malware analysis report

Static analysis result for SHA-256 f12c6a5c98183295…

MALICIOUS

PDF

78.7 KB Created: 2021-03-19 18:44:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e1c6191ec0ddcb4114b5b920c25b98fd SHA-1: 7aad31f0ddf3ed937da7cf14f6222810242fd9da SHA-256: f12c6a5c981832952b8cfeae4c174894a7384c9bf21aee7d990f33f725823a0c
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. It contains numerous external URIs, many hosted on disposable domains, suggesting a link farm designed to redirect users to malicious content. The document body, though heavily obfuscated, appears to be a lure related to 'critical thinking skills', likely to trick users into clicking the embedded malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=critical+thinking+skills+among+nursing+students
    • https://static.s123-cdn-static.com/uploads/4488103/normal_6002369f3c88a.pdf
    • https://static.s123-cdn-static.com/uploads/4459036/normal_5ffe84aa50807.pdf
    • https://xumijarivibamow.weebly.com/uploads/1/3/5/3/135339210/06d65f1ecae33.pdf
    • http://afracheat7.xyz/lifesmart_infrared_heaters_reviewshwn1i.pdf
    • https://papenuxid.weebly.com/uploads/1/3/0/8/130874395/bimesoma_jusogijitenul_bagol_lakuxi.pdf
    • http://feyakast.online/balixotexufosovifztfxt.pdf
    • http://zokiwedilar.mypressonline.com/21441608074.pdf
    • http://rikafitamedad.medianewsonline.com/41180780780.pdf
    • http://romeita.space/flower_un_amor_intensowj8kh.pdf
    • http://best-store.club/ap_biology_chemistry_of_life_study_guidel8p6j.pdf
    • https://guxulixekakuved.weebly.com/uploads/1/3/5/2/135294256/jezak_vivexaro_vuzizujopuzugox_monos.pdf
    • https://cdn-cms.f-static.net/uploads/4388842/normal_601301619c659.pdf
    • https://cdn-cms.f-static.net/uploads/4412573/normal_603a40034cc05.pdf
    • https://cdn-cms.f-static.net/uploads/4445532/normal_6048ec3412181.pdf
    • https://tubozabuzimez.weebly.com/uploads/1/3/4/8/134878922/ee0f5e54b85c176.pdf
    • http://hookup157.fun/wuzisijalugupidulewacv7nx.pdf
    • https://leniwexobopusez.weebly.com/uploads/1/3/4/7/134713406/jagakuvunusuti_vazazanomajol_woxevelalawapa.pdf
    • http://sodahub.pro/corporate_social_responsibility_community_developmentzst8r.pdf
    • http://demask.fun/fitatixoxumesiszd4z.pdf
    • http://zavolofa.mygamesonline.org/battery_ignition_system.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/2a49f61f-ba26-46df-b26e-96e8d0363c5b/9248567378.pdf
    • https://uploads.strikinglycdn.com/files/674c12fe-96ce-4589-b8ad-dae6c9f1a193/80126301051.pdf
    • https://uploads.strikinglycdn.com/files/1b079771-b74f-4420-9f7f-ab0bea1c4fb0/momodopaw.pdf
    • http://zapusov.atwebpages.com/distinguish_between_fundamental_analysis_and_technical_analysis.pdf
    • https://uploads.strikinglycdn.com/files/28cc6fb7-6470-45f2-a4a9-abdd920f389a/reddy_heater_30000_btu_thermocouple.pdf
    • https://uploads.strikinglycdn.com/files/676b7249-53fe-459a-ab8b-1b263c83f829/55330759349.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f703.bin
694bf461969c017b9cfa987d417e0cd526e8c0273ec505c999934903e71c3321
pdf-font-stream PDF embedded font (sfnt) at offset 0xF703 5320 bytes
font_01_sfnt_off000108e4.bin
4ef34ad16a55bf63213884a983a800d3dbebc779e868f99b2e5a9e267a94dda8
pdf-font-stream PDF embedded font (sfnt) at offset 0x108E4 10504 bytes