Malicious PDF — malware analysis report

Static analysis result for SHA-256 facd9934f0611448…

MALICIOUS

PDF

76.1 KB Created: 2021-03-16 13:09:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bd49ad8255b0f51e6f984d9cccdd1fd6 SHA-1: b9eddff5e2d114f9eced83fd5cc074a2425b4259 SHA-256: facd9934f0611448e0cb4b3450bdcea450a6bfce27a25ef9804408c1410651f4
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are SEO-optimized and point to other PDFs, indicating a link farm or SEO spam operation. The primary URL, 'https://seumenha.ru/wix?keyword=tour+guide+job+duties', suggests a lure related to job duties. ClamAV detection and ML classification strongly indicate malicious intent, likely for phishing or distributing further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=tour+guide+job+duties
    • http://patedeziw.mypressonline.com/rukeribubig.pdf
    • https://cdn-cms.f-static.net/uploads/4420459/normal_601ec711bb4dd.pdf
    • http://midunetojonawiw.mywebcommunity.org/agenda_examples_for_staff_meetings.pdf
    • http://beguwidip.scienceontheweb.net/ortopedia_y_traumatologia_panamericana.pdf
    • https://cdn-cms.f-static.net/uploads/4480591/normal_602424e23861b.pdf
    • http://nebuxopav.mypressonline.com/symptoms_of_malaria_parasite.pdf
    • https://cdn-cms.f-static.net/uploads/4495387/normal_60496b51dc4a9.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/xefezesebusu/alkane_alkene_alkyne_table.pdf
    • https://uploads.strikinglycdn.com/files/73367a47-7c83-4b79-b49a-4c21a62429ca/29572257124.pdf
    • https://uploads.strikinglycdn.com/files/9ec5c308-7bb9-4022-a962-c819fe61e680/what_is_best_sat_prep_course.pdf
    • https://s3.amazonaws.com/jujadodedaruxix/tudenisoji.pdf
    • https://30b7a97f-6117-4fff-8876-4b3c2220b6c6.filesusr.com/ugd/15cd4d_67ec24fb5eaf4de0a956ea021b100d30.pdf?index=true
    • https://s3.amazonaws.com/zalisujezajaje/50542380072.pdf
    • https://s3.amazonaws.com/kozibowisenatu/shopping_list_html_template.pdf
    • https://s3.amazonaws.com/rivazixexuguri/98005353338.pdf
    • https://uploads.strikinglycdn.com/files/78b30b32-ce9c-499d-81f2-58d110eef6a3/lupofexomavur.pdf
    • https://uploads.strikinglycdn.com/files/48cc9bcf-1e54-4a7d-ac5c-71a1a790a3be/quadratic_equation_using_quadratic_formula_examples.pdf
    • https://uploads.strikinglycdn.com/files/69fd4446-ddfe-4708-bc68-744604d11809/yamaha_rx-v373_bluetooth.pdf
    • https://ce2645ba-e89a-43d5-afff-5c0150757291.filesusr.com/ugd/c63dba_a9b70c85072943029ebb186c1bea37c1.pdf?index=true
    • https://s3.amazonaws.com/nasitevu/equality_before_the_law_definition_history.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eeb5.bin
aa60c9e542e1eda3f4136d41f36e62db03f492673d9c5eea650412154744f9e2
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEB5 4916 bytes
font_01_sfnt_off0000ff81.bin
06b51eb943738b9aeba2866c44c2241d09fbd346757a6c15c8a3c9de2cdb7461
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF81 10556 bytes