Malicious PDF — malware analysis report

Static analysis result for SHA-256 11e9b36f7128d901…

MALICIOUS

PDF

75.7 KB Created: 2021-03-19 08:05:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 6f5542020a916e24b92d2928a89d02d1 SHA-1: 98a574fe209c45d02aa09c9734a70623d5957637 SHA-256: 11e9b36f7128d901ebeff12626bf01efe1011b9bdfe235b475667e7c69035ef4
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, with a high concentration of them pointing to disposable hosting or suspicious domains, indicating a link farm or phishing attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of a phishing or malware distribution vector, likely leveraging spearphishing attachments.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/award?keyword=elementos+del+genero+dramatico+pdf PDF link annotation
    • http://mufadetajamojo.iblogger.org/lalaxumawatofezasezi.pdfIn PDF document text
    • http://wasegulom.mygamesonline.org/4973804101.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4497685/normal_5fe1d661eeb3d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4407081/normal_604cc79a54c4b.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4445743/normal_5ff69eb1670fb.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://felalosekubav.epizy.com/industry_report_definition.pdfIn PDF document text
    • http://pidisoxoxaxar.rf.gd/how_to_understand_router_logs.pdfIn PDF document text
    • https://66ce1c92-167a-49d0-a058-8ecba4f8bde6.filesusr.com/ugd/3835dd_969fe5be9a8c4c5785f64427ec9dabd9.pdf?index=trueIn PDF document text
    • http://jewuwururutaf.epizy.com/california_dmv_forms_title_transfer.pdfIn PDF document text
    • http://tijuvewoduga.onlinewebshop.net/xurupadabilogijetotibag.pdfIn PDF document text
    • http://bimemelal.epizy.com/pdf_password_cracking.pdfIn PDF document text
    • https://3e1d1bad-f645-4ebd-ac75-469e7ff7c972.filesusr.com/ugd/e745be_4f48d6049fbd4588956e9a5396ace901.pdf?index=trueIn PDF document text
    • http://divojeniro.epizy.com/does_the_red_cross_test_blood_donations_for_covid_19.pdfIn PDF document text
    • http://litabasiker.onlinewebshop.net/cambridge_primary_progression_test_stage_5_mathematics.pdfIn PDF document text
    • https://2d2b1dae-c014-4902-97e6-c3f1d56915cd.filesusr.com/ugd/70e5f7_1a0a8210111143f9aefe7a9e44e4ee99.pdf?index=trueIn PDF document text
    • https://68358877-4ee6-4e53-94f7-4bd9665c1f53.filesusr.com/ugd/3bbd68_fbc70cc2ba1243839e3548091726c2e6.pdf?index=trueIn PDF document text
    • http://xupudajiwozov.epizy.com/vk_publications_accountancy_class_12_solutions.pdfIn PDF document text
    • https://3a5aa097-47f9-475f-9992-83bceef25cc3.filesusr.com/ugd/f55bec_d3af05620ede481a87b18519a98b14f8.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea42.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEA42 5432 bytes
SHA-256: 108701f71a4783462943c76f459836a908d075f16b21092194d6ded270a01a88
font_01_sfnt_off0000fca9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFCA9 11032 bytes
SHA-256: e153f6948ba1fc72d5a2cf36f0446fb77c4216ce4b9e9e6cab96f6657a017025