Malicious PDF — malware analysis report

Static analysis result for SHA-256 26ac5a9b4060b33c…

MALICIOUS

PDF

79.6 KB Created: 2021-03-15 21:21:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e5585e1a65f723f71ff2f4f3ee7e00d7 SHA-1: f270a2af31bdade09d812b4215101f14b79ff949 SHA-256: 26ac5a9b4060b33ccec6e6601a0d3f572787a3ec342780340f513e8fe6b7e283
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, many of which point to disposable hosting and are flagged as part of a link farm. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URIs suggest it's designed to redirect users to malicious sites, potentially for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/award?keyword=addressing+modes+of+8086+pdf
    • https://cdn.sqhk.co/rupizabiweze/gi5jjjg/9674539119.pdf
    • http://vilopeg.xyz/25410099212hptqu.pdf
    • http://wojisub.mypressonline.com/lymphatic_system_diseases.pdf
    • https://cdn-cms.f-static.net/uploads/4413125/normal_60282e3dadee2.pdf
    • https://cdn-cms.f-static.net/uploads/4366389/normal_601db2be86174.pdf
    • https://cdn.sqhk.co/bapuwanuvadi/jiGgiHY/golden_boot_winners_2020_premier_league.pdf
    • http://parkingtest.xyz/tamikobco7qk.pdf
    • http://nubidatum.22web.org/21359407951.pdf
    • http://zarabatyivat.ru/jubinezibazelaworamufovef3oa1l.pdf
    • http://gifudevuf.iblogger.org/apics_certification_study_guide.pdf
    • http://tobufupevujuma.mygamesonline.org/how_to_heal_from_child_trauma.pdf
    • https://cdn.sqhk.co/wiwevini/egdD6Ac/movies_playing_near_me_today_regal.pdf
    • http://piter.store/xosijekonazaw2u29m.pdf
    • http://gosoxegekiri.mywebcommunity.org/good_evening_in_spanish_pronunciation.pdf
    • https://static.s123-cdn-static.com/uploads/4458412/normal_5ff861cdf037e.pdf
    • https://cdn.sqhk.co/keridola/iamgczd/ice_fire_wolf_wallpaper.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://kebanibaru.epizy.com/pezunogazidamidaxadaja.pdf
    • http://vefodipox.myartsonline.com/84889481680.pdf
    • http://sajogaluka.rf.gd/zip_codes_by_county_map.pdf
    • https://s3.amazonaws.com/muvarelo/mozeluged.pdf
    • https://s3.amazonaws.com/robumuduluwise/analyst_s_guide_to_indicators.pdf
    • http://nibemodida.myartsonline.com/toro_521_snowblower_wont_start.pdf
    • http://borebatibi.rf.gd/shanghai_p_c_information_technology_co._ltd.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebc9.bin
223cce1e005be6e4272086256548ad5f11d9dd63ea7472fcff035b6d48841264
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBC9 5304 bytes
font_01_sfnt_off0000fdaf.bin
11612a6bbf9541b426d61b2761f0fe97751ca64b23766cac70f654f02c307af2
pdf-font-stream PDF embedded font (sfnt) at offset 0xFDAF 10920 bytes
font_02_sfnt_off000122d8.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x122D8 4324 bytes