Malicious PDF — malware analysis report

Static analysis result for SHA-256 21e7bc342a7db6cf…

MALICIOUS

PDF

91.2 KB Created: 2021-03-08 16:17:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-26
MD5: d0a3e53fe3e9b3882badbbc9a2301e1f SHA-1: 9b38ce0628e78d197645ba4b8973e4e075c93d10 SHA-256: 21e7bc342a7db6cf01ee805c8e654e88add001fc57bf45c910d5a4562e42fcab
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs, with at least one identified as a malicious redirector. The ML classifier and ClamAV detection strongly indicate malicious intent. The document body, though heavily obfuscated, contains text related to downloading a PDF, aligning with a phishing or malware distribution lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/award?keyword=download+tabel+asmaul+husna+pdf In PDF document text
    • https://cdn.sqhk.co/ranetixeba/iBrXljd/mozixop.pdfIn PDF document text
    • http://fibutogu.mywebcommunity.org/extrinsic_pathway_of_apoptosis.pdfIn PDF document text
    • https://cdn.sqhk.co/zerurukoraju/jeiidgd/snapping_turtle_eggs_hatching_video.pdfIn PDF document text
    • http://zegererevez.medianewsonline.com/31535081523.pdfIn PDF document text
    • https://cdn.sqhk.co/dukosisevu/hajarJN/international_calls_from_us.pdfIn PDF document text
    • http://kidufamipowanot.mywebcommunity.org/99690957939.pdfIn PDF document text
    • https://cdn.sqhk.co/xojelumegasi/Szgh4SS/76632823995.pdfIn PDF document text
    • http://rebibedo.mywebcommunity.org/libem.pdfIn PDF document text
    • http://zekojotewakugag.mypressonline.com/lukobanopovi.pdfIn PDF document text
    • http://fuzubijixulux.mygamesonline.org/23321619874.pdfIn PDF document text
    • http://zisuroto.mygamesonline.org/surely_youre_joking_mr_feynman_audiobook.pdfIn PDF document text
    • https://cdn.sqhk.co/detatakev/jzKgejf/norolimudowamowonerus.pdfIn PDF document text
    • http://,,,,,ul,,Husna,,1,,,Allah,Allah,,,2,Most.,,,,MuizIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/4aa9f878-cebc-45df-9028-c0151d65f769/kobowoki.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3abf1237-850c-4155-80ec-bd5fb22557f0/jepef.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bc5ed36f-b3f3-4276-bf47-cad2d3abdb48/how_to_turn_on_vizio_subwoofer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4b2acb81-8b75-4578-b387-2c92ddbf30b2/todepawijewovajevugavenuk.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/737e8a03-b03e-4912-a66d-529a6de09df8/garelesisirupuxe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/38b57210-b7b6-443c-bb4c-12e166270757/daisy_powerline_880_pump_repair.pdfIn PDF document text
    • https://s3.amazonaws.com/bewibiwat/how_to_write_a_performance_review_goals.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0d38a729-98da-46aa-8abf-62c25ebc8778/kyocera_ecosys_m2540dw_operation_guide.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e0b3153d-636f-49b4-bd29-c586a918ae72/70173868740.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b7a58f1d-862f-4ce5-ae40-b86562c03634/roles_by_complex_selection_criteria.pdfIn PDF document text
    • https://s3.amazonaws.com/sobaketemu/adblock_fast_apkpure.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5be.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF5BE 3104 bytes
SHA-256: 24551eddf735aab63d4c7e1e241f9f40a571c0286a9358847cb31cf4386de53e
font_01_sfnt_off000100d1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x100D1 5416 bytes
SHA-256: 2de780c6df5719e4844a829892a1363512e9d72bf02ee9c2887a374a4c63bc35
font_02_sfnt_off0001132b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1132B 13028 bytes
SHA-256: 16bd54e03e9070cc3ae7417dadc8652768a1c22b9ed38841e7e3324c362b5964
font_03_sfnt_off00013c75.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13C75 20240 bytes
SHA-256: 553eeed94f6cf9df30852e45be66ffd559bde0a032d4ccf81dad912d3263e016