Malicious PDF — malware analysis report

Static analysis result for SHA-256 08581fbbd30047f2…

MALICIOUS

PDF

74.8 KB Created: 2021-09-20 21:16:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 7878720cfe73b8ea3024d5265504c51d SHA-1: 4a5500a20333b4a945c8c59f43163619fa6d4a21 SHA-256: 08581fbbd30047f2e35e962f2673fb5840fe747ffebd0d1d97ebeaffc137b883
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs, many of which point to disposable hosting and are part of a link farm. One critical heuristic indicates it's a phishing/trojan PDF. The presence of external URIs and the link farm structure suggest the primary goal is to redirect users to malicious sites, likely for phishing or to download further malware.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3887

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://coretry.ru/uplcv?utm_term=football+manager+2020+download+free+android
    • http://studiosimonepantaleo.it/userfiles/files/79709587798.pdf
    • https://detskeihriska.eu/ckfinder/userfiles/files/goritawazugisaxifan.pdf
    • http://sm300159.agchost.com/userfiles/files/wugolimezazimalidojalefu.pdf
    • https://olivierdaulte.com/ckfinder/userfiles/files/65836062851.pdf
    • https://dananeye.com/uploads/files/202109170807199533.pdf
    • http://noclegsosnowiec.pl/eurostyl/photos/file/wowaraj.pdf
    • https://sunnyrosesschool.com/userfiles/file/3017384009.pdf
    • https://samirkumarpaul.com/ckfinder/userfiles/files/kosovaninoxesegasi.pdf
    • http://sartor.ru/upload/files/26712151745.pdf
    • https://seerupit.dk/assens/file/zatejogumokora.pdf
    • http://swapnakoodu.com/fck_uploads/file/98626808272.pdf
    • https://milosislandrooms.gr/userfiles/file/kozojidowulal.pdf
    • http://pc580.cn/upload_fck/file/2021-9-18/20210918051124748264.pdf
    • https://lionkingbali.com/uploads/file/22433548863.pdf
    • https://elemental-ia.com/userfiles/file/5814857249.pdf
    • http://colorfusion.us/admin/images/file/77563365570.pdf
    • https://asiquim.com/ckfinder/userfiles/files/mokurexarop.pdf
    • http://brbud.pl/userfiles/file/22260657694.pdf
    • http://mos-craciun-inchiriere.ro/fckfiles/file/98216444309.pdf
    • http://roseeskin.com/userfiles/file/20210911150550.pdf
    • http://kaymccarthy.com/immagini/file/najovitirakumor.pdf
    • http://toanlinh.vn/upload/files/37904364521.pdf
    • http://sluchatka-shop.cz/files/upload/files/23852400225.pdf
    • https://planningpvedh.nl/ckfinder/userfiles/files/magedoremete.pdf
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b78a.bin
fa5cbea137587b1d4bb1c548ff3f8d17a18587fe273de630a8d80f12e69f99e4
pdf-font-stream PDF embedded font (sfnt) at offset 0xB78A 16160 bytes
font_01_sfnt_off0000cd21.bin
b9787f78ebcdb8a9bf780f00c79981e0142fc67718b08722b07b29b265edb3fc
pdf-font-stream PDF embedded font (sfnt) at offset 0xCD21 20668 bytes
font_02_sfnt_off0000fff5.bin
435a6d4c2614142bca364bab974ab6f80e9752202693e90c14ef394ec9dc7e27
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFF5 10972 bytes