Malicious PDF — malware analysis report

Static analysis result for SHA-256 030f8efaafa59928…

MALICIOUS

PDF

92.0 KB Created: 2021-03-31 01:53:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 75563fff6988405a6f8f8e486eaf8bb3 SHA-1: 2f3c266f678c9a5003d12bd5a87b153e1d3aa744 SHA-256: 030f8efaafa59928204b2af0b193192ce33b8c1d743386eec9c6e4eea35e35f2
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing indicating it links to known malicious redirector infrastructure, specifically to the URL https://dafemum.ru/award?keyword=pearson+campbell+biology+textbook+pdf. This suggests the document is designed to lure users to a malicious site, likely for phishing or to download further malware. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/award?keyword=pearson+campbell+biology+textbook+pdf In PDF document text
    • https://cdn.sqhk.co/rivogigaweb/ihhaggd/kenimikeji.pdfIn PDF document text
    • https://cdn.sqhk.co/minederepa/gThahd5/kujexodajurizonumur.pdfIn PDF document text
    • https://cdn.sqhk.co/jujadiziga/hgHgjia/zunoxiv.pdfIn PDF document text
    • http://wutobunuponumed.22web.org/libus.pdfIn PDF document text
    • https://cdn.sqhk.co/xenudipu/4tgj0MD/kaiser_permanente_flu_shot_2020_fremont.pdfIn PDF document text
    • https://cdn.sqhk.co/vobevufubito/ifQjaie/20552557424.pdfIn PDF document text
    • https://cdn.sqhk.co/vitimosugu/db9gPzF/lujesu.pdfIn PDF document text
    • https://cdn.sqhk.co/sovanoniwuva/ijiiAhb/uber_driver_close_to_me.pdfIn PDF document text
    • https://cdn.sqhk.co/nenuguvan/PH6hjib/bafojenodujejudoz.pdfIn PDF document text
    • https://cdn.sqhk.co/vugomupuzisa/r1ibghP/sodagupewipizafameraxodu.pdfIn PDF document text
    • https://cdn.sqhk.co/satasevubu/h3iSGii/transferwise_money_transfer_fees.pdfIn PDF document text
    • https://cdn.sqhk.co/sunalikefazo/ijihiia/samsung_voice_recorder_recording_failed.pdfIn PDF document text
    • https://cdn.sqhk.co/vexavudakepa/hdyjiMh/best_deals_vestige_online_shopping.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/7a0351ce-7b5c-4960-babe-1f09dc7cf6c3/skyworth_40_class_fhd_1080p_led_tv_40e2_reviews.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ddb6431f-bde0-4a70-bbea-0de31a084a0f/how_to_draw_a_dog_step_by_step.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/409c1273-903a-4fc1-abad-f4b1cce64a5e/manual_de_organizacion_de_una_empresa_textil.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/29925f0b-992a-47e1-9be2-8d1aec492dd2/the_strongest_quotes_about_life.pdfIn PDF document text
    • http://monulaw.epizy.com/aqeedah_wasitiyyah_urdu.pdfIn PDF document text
    • http://kizobenunag.rf.gd/simofepuvidupu.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001291b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1291B 5852 bytes
SHA-256: 54579618909dd36d1866d7418fee283929e5091452f93d2ec41dabddc1e44b46
font_01_sfnt_off00013cfa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13CFA 11176 bytes
SHA-256: add41e5893e0715f8ab67af8c7cb41b829e74b25979588244357a3af1ac19a92