Malicious PDF — malware analysis report

Static analysis result for SHA-256 034459fa56267042…

MALICIOUS

PDF

89.2 KB Created: 2021-09-19 16:59:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 7d3ef31136b73bb59ae61b790b9c8d03 SHA-1: 93b1a65a760d0291c03731cdc225a0fd9f0d354a SHA-256: 034459fa56267042d48acda46272abb285ec950d530becd1c1cdfd285dfd21ef
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The file was detected as malicious by ML classifiers and ClamAV, specifically identified as a phishing trojan. It functions as a link farm, containing numerous embedded URLs pointing to various domains, many of which are hosted on disposable infrastructure. The PDF's structure and the presence of many distinct hosts suggest an attempt to distribute malicious content or phish users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9937

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kapalishakti.com/ckfinder/userfiles/files/sexisirifogaxikezaf.pdf
    • https://sieuthigo.vn/upload/ck/files/wedujavajalo.pdf
    • http://fapannimario.it/userfiles/files/76695291234.pdf
    • https://www.soroptimist.be/oldsite/intranet/ckeditor/ckfinder/userfiles/images/files/piwigigusuzolo.pdf
    • http://www.pavimentosyreformasferlu.es/ckfinder/userfiles/files/98195408296.pdf
    • https://institut-arabe.org/ckfinder/userfiles/files/dirujude.pdf
    • http://integrotech.pl/zdjecia/file/rukafezijizetivesuv.pdf
    • http://paintingservicesonline.ca/wp-content/plugins/formcraft/file-upload/server/content/files/161387e1255d93---97141223760.pdf
    • http://lauraestetica.com/userfiles/files/tegetogix.pdf
    • https://dulsuc.cl/userfiles/file/90179367398.pdf
    • http://refpecsbelvaros.hu/kepek/files/jakupapus.pdf
    • http://a-pluset.com/userfiles/gopuxozunakotifexadek.pdf
    • http://corporatiegids.nl/uploads/files/86090119658.pdf
    • https://xn--80aaa1anac6cg.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/b480bca7caa07e8186d8807e9c089287/nimuladelazolatamapajo.pdf
    • http://ultrabeauty-ff.ru/userfiles/file/wosetujevozenalilo.pdf
    • http://themadthinker.com/temp/vinney/HTML/userfiles/file/16860093125.pdf
    • http://baschin-heizung.com/meineBilderAlbertGrundschule/file/pitav.pdf
    • http://rentator.com/uploades/fckeditorfile/5860795388.pdf
    • http://lingeriedediva.com/UploadFile/file/2021090702473573499.pdf
    • http://factorycontrolprojects.com/userfiles/file/pekifol.pdf
    • http://chamdure.com/DATA/files/18362095073.pdf
    • https://sukhayurveda.in/userfiles/file/godid.pdf
    • http://inbjnews.com/data/cheditor/0603/files/roduxama.pdf
    • https://domilot.com/uploader/files/77142746081.pdf
    • https://nacituran.com/userfiles/file/pezodejosepasalijivikaw.pdf
    • https://feedproxy.google.com/~r/skout/mBVl/~3/YTWXjIUwRh0/uplcv?utm_term=marvel+vs+capcom+2+apk+mega
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f675.bin
08135e6a94458fa13874cc517ce79f7c1ec179fa4ff4064e7cadd8486db188f2
pdf-font-stream PDF embedded font (sfnt) at offset 0xF675 18324 bytes
font_01_sfnt_off00012687.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x12687 16792 bytes
font_02_sfnt_off00013e9e.bin
61a52959ecbe4a966e0f5f53ea429613f82a81421918afb85a394676d7ab6583
pdf-font-stream PDF embedded font (sfnt) at offset 0x13E9E 10696 bytes