Malicious PDF — malware analysis report

Static analysis result for SHA-256 1001486b2dbcf7de…

MALICIOUS

PDF

148.8 KB Created: 2021-03-19 06:50:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-17
MD5: 066565a4bda135e9facd444408629f3c SHA-1: c6f1f66a0d41f8d47611f5784c234a717401f399 SHA-256: 1001486b2dbcf7de478ecfc446bb18a9b0689d1835ebaa2467605a69c3d53b16
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains embedded URLs and is flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. The document body, though heavily obfuscated, suggests a lure related to 'Uses of benzene pdf', likely intended to direct users to malicious sites for phishing or further payload delivery. No scripts were extracted, but the presence of numerous external URIs indicates a strong intent to redirect the user.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9981

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/award?keyword=uses+of+benzene+pdf PDF link annotation
    • https://cdn.sqhk.co/mezutowede/Xuifgdv/87247734616.pdfIn PDF document text
    • https://cdn.sqhk.co/sufipuxifemo/hjaifz5/sotukopubupizedekopazes.pdfIn PDF document text
    • http://rawutunulodewo.iblogger.org/32297399841.pdfIn PDF document text
    • http://papotupeti.iblogger.org/jarif.pdfIn PDF document text
    • https://cdn.sqhk.co/janezewufaj/fhfBcHh/cam_random_video_chat_app_download.pdfIn PDF document text
    • http://zezasarasojid.mywebcommunity.org/sufususiwuludotoxogoxab.pdfIn PDF document text
    • http://taforojujutusig.mygamesonline.org/64786183956.pdfIn PDF document text
    • https://cdn.sqhk.co/xakatikakizi/TRtWfji/hurricane_outbreak_apk_mod.pdfIn PDF document text
    • http://jubigale.scienceontheweb.net/76717761425.pdfIn PDF document text
    • https://cdn.sqhk.co/govulasem/hjZgcji/bubble_shooter_apps_for_android_phones.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://51f47fa2-20f7-4ec4-bb91-8ae4aee689b4.filesusr.com/ugd/917232_89f0a43eb0244e2fab864d4920d1f4a0.pdf?index=trueIn PDF document text
    • http://wotituxisu.rf.gd/masemufasezawenibuj.pdfIn PDF document text
    • https://b7eb3c74-9f10-4efd-a612-efb7ea03662f.filesusr.com/ugd/7198c1_c20a164b9e7d414fb45688bdcc98e1e8.pdf?index=trueIn PDF document text
    • http://suxazetevuzo.onlinewebshop.net/lagopuxotapizufewapume.pdfIn PDF document text
    • https://2a4c341d-9af7-4f89-b48a-1b926ad6ced7.filesusr.com/ugd/dd6616_5214c402c5bf4d52b83c989a929fb6d2.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/wanalovum/chadariya_jheeni_re_jheeni_video.pdfIn PDF document text
    • https://b42dfab6-8227-42c4-8fe5-fc04d9433513.filesusr.com/ugd/a9a8df_833326d0ee1b41aabd74f7a22fed2168.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/lixasifasi/73555553225.pdfIn PDF document text
    • https://s3.amazonaws.com/vutame/what_did_the_bantu_spread.pdfIn PDF document text
    • https://s3.amazonaws.com/gomakobez/2498228917.pdfIn PDF document text
    • https://47a25507-5c4f-4e73-9b7c-0c49514c8174.filesusr.com/ugd/e00bd3_9617d463d55e4a1f8566613d5b75a137.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001dcd1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1DCD1 6492 bytes
SHA-256: d2077f5d6d5b1d677d9b6d000eb087611a047961d42ceeb980acba3b54af8b85
font_01_sfnt_off0001ed06.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1ED06 4880 bytes
SHA-256: d67959de241105ffe5ac27c90a0a6dd57242f24fc5a4285d2872a0c44ebfd0b7
font_02_sfnt_off0001fdbd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1FDBD 15308 bytes
SHA-256: f55a59311eab4b24b85b1a5378e9c9aecaad73cb3b4251bffeab8b6dbefaa18e
font_03_sfnt_off00022f1e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x22F1E 16456 bytes
SHA-256: 783549d956e361c70250ffa405bf48ece8976407c9b27d72be8cdc04c5af5ecd