Malicious PDF — malware analysis report

Static analysis result for SHA-256 17410472f109e719…

MALICIOUS

PDF

179.3 KB Created: 2021-03-17 23:47:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-02
MD5: 6989586413f63b9928a6e2452170d36d SHA-1: c7b5900bb940783746a134f47d2ee926e34cfd2b SHA-256: 17410472f109e7194a98fe34c6022644afe10a971b3d44cd438873abeab30451
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, with a significant number pointing to disposable hosting and acting as a link farm. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and numerous external links suggest it's designed to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7322

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=om%2526m+second+and+sebring+lyrics PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4420766/normal_6019b43b4d591.pdfIn PDF document text
    • https://cdn.sqhk.co/tixunadegu/jcAgiGO/kakaostory_app_download.pdfIn PDF document text
    • https://cdn.sqhk.co/sokulutesi/ajg1ja5/miley_cyrus_slide_away_video_music_awards.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365563/normal_604d90e19d756.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4392868/normal_5ffeb872ca043.pdfIn PDF document text
    • https://meligobuv.weebly.com/uploads/1/3/1/0/131070858/mesukab-fozizawem-zogasudinen-visabufirug.pdfIn PDF document text
    • https://cdn.sqhk.co/mibemofega/jfwQuja/wedojabugefe.pdfIn PDF document text
    • https://cdn.sqhk.co/befozaxulot/ddhZja7/kunewomepufasepamesuranu.pdfIn PDF document text
    • https://cdn.sqhk.co/suxujaba/9xkijhg/maxillary_lateral_incisor_root_formation.pdfIn PDF document text
    • https://cdn.sqhk.co/juvowisire/zCidrgg/dinos_online_enemy_mod_download.pdfIn PDF document text
    • https://fetepidema.weebly.com/uploads/1/3/4/6/134684810/477df54d2cd.pdfIn PDF document text
    • https://cdn.sqhk.co/rekubapapup/lhwhdjb/wakaf_al_quran_malaysia.pdfIn PDF document text
    • https://jubitire.weebly.com/uploads/1/3/4/0/134017652/a3ec2d941f0ed3f.pdfIn PDF document text
    • https://lojumokixawivi.weebly.com/uploads/1/3/4/3/134370302/184474.pdfIn PDF document text
    • https://cdn.sqhk.co/titesojijuko/ijghBwA/scummvm_backyard_baseball_mac.pdfIn PDF document text
    • https://gixunilaw.weebly.com/uploads/1/3/1/8/131856646/gubiwizajisivalivar.pdfIn PDF document text
    • https://xadafujivesa.weebly.com/uploads/1/3/1/3/131397927/lifofozoroxibe.pdfIn PDF document text
    • https://cdn.sqhk.co/lexelinowe/HdWhg79/cannonball_tv_show_contestants.pdfIn PDF document text
    • https://nerisowale.weebly.com/uploads/1/3/1/4/131412290/c0a3b94fa5eb.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470839/normal_6022842354259.pdfIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • http://www.thdl.org/http://www.thdl.org/TibetanIn PDF document text
    • https://uploads.strikinglycdn.com/files/d0421fc7-fd5d-4e1b-9a34-1175d83491ea/the_one_year_chronological_bible_study_guide.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e48b5984-921d-4881-8c60-82a9516d4702/81820801781.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/02361310-4845-4d65-8689-8ed9ee92c92a/how_to_fix_overscan_on_tv_windows_7.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2cf77174-51e9-4845-9718-d4eb75c20721/28188211511.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3792f6bf-2247-4239-a8b6-4d4492389b24/how_to_improve_memory_psychology_today.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • http://sinhala.sourceforge.net/In PDF document text
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
    • http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text
    +5 more URL(s)

Extracted artifacts 19

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018212.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18212 2700 bytes
SHA-256: 4b5a92cc47b7983f026ea3ff56d7aaf5802c5b14b1b4698a1757b2a5b828b510
font_01_sfnt_off00018cb3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18CB3 12092 bytes
SHA-256: e3b694ff1d953d44f135d57e219cf02d97160729ef5e712ffded0e6a2b8a493f
font_02_sfnt_off0001b27e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1B27E 6768 bytes
SHA-256: f2c3ae27c622785b276c10cec108896e8f0c950279f69f2828411d04d7807570
font_03_sfnt_off0001c43d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C43D 14492 bytes
SHA-256: 90b5b0c949cb3f0fff1c8f16e3e2c6a33e3bcd4cdc2e097b420b0e534b79aa64
font_04_sfnt_off0001eeae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1EEAE 4336 bytes
SHA-256: ce0d9eb797d8cf9ccaedd51ea3ad9cb50acae36e25bc01a50bec5f3dc3c56a1b
font_05_sfnt_off0001fd59.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1FD59 2328 bytes
SHA-256: 44767bda6b00968c16a5029afc21f93e914175494fe70d5df426bb9f84af37f2
font_06_sfnt_off00020774.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x20774 2588 bytes
SHA-256: 917c19bc2c6b173bcf142764ef72d4801811febe02a29a3bcb2513d144cc64a4
font_07_sfnt_off000211c5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x211C5 2476 bytes
SHA-256: 73a1bb60e37fcb34b20043ddfa274a0d0f146338f7f0d3214e4d32654df68dba
font_08_sfnt_off00021c29.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x21C29 4552 bytes
SHA-256: a3f933d7d46d9cd16b277c4bc47c618e1d53cb50efdb7a3137c6af4462dcc819
font_09_sfnt_off00022c57.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x22C57 16392 bytes
SHA-256: 03c046c1feffb40f00006eba41f02927736f4947977a81dc07cd1091f9cd9058
font_10_sfnt_off000242b8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x242B8 4120 bytes
SHA-256: 61e9d60b0f2ccae62527326f830fa621b32442c899909d4798848d222ddfeeba
font_11_sfnt_off00024f8f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x24F8F 3092 bytes
SHA-256: 9214e94aafecc53ab94d37daf2bd6204090719c5adf570fef43d4c775c21f296
font_12_sfnt_off00025b5c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x25B5C 9032 bytes
SHA-256: d3efe01c8b8479868b1699180a7bc98a54da26bd7f89d1debfc700996049809b
font_13_sfnt_off000272f8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x272F8 1752 bytes
SHA-256: f282e13af532e01ad7fb5d254810ff0912ebb7b391498b216dca6a212321f58c
font_14_sfnt_off00027c0f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x27C0F 3948 bytes
SHA-256: a3f2861cb6ba983c1097ab9f42bf0a43bb2ec6939b078bebd53d4a274ae88b94
font_15_sfnt_off00028836.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x28836 3804 bytes
SHA-256: af17c5ec1580e8b011ba0c4df87a0e018cd32746ca3bc0a355f74f8912b1593b
font_16_sfnt_off000294a0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x294A0 1756 bytes
SHA-256: 11bdc9b6cccd59c0f6dc96e192531a97844b109a91f75fd61d98f24a3d0d6759
font_17_sfnt_off00029dac.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x29DAC 1828 bytes
SHA-256: ff36e7b2d728e7293fba5764f8bfa1508a6e6a54f1e6f627b069b9b7edc9c69c
font_18_sfnt_off0002a6ae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2A6AE 9052 bytes
SHA-256: 541b88f9f567e242d10080059918ced9857c43f45ae0ac49223afa872c30778a