Malicious PDF — malware analysis report

Static analysis result for SHA-256 315a6af306865915…

MALICIOUS

PDF

116.0 KB Created: 2021-04-20 22:57:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: a8907d85c70cbb27d15eb12952d9397b SHA-1: 2eb106c52be4beebacad7cd1df2a37d69ce27c1f SHA-256: 315a6af3068659157c9ea4898d21af94607453f532d96bf83a4cdc8a783f78d9
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous embedded links, many pointing to disposable domains, suggesting a phishing or scam attempt. The heuristic 'PDF_SEO_DISPOSABLE_LINK_FARM' indicates a deliberate effort to create a link farm on potentially malicious hosting. The presence of external URIs and the ML classifier output strongly support a malicious classification. Although no scripts were explicitly extracted, the structure and embedded links are indicative of a phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=queen+of+shadows+tv+series+where+to+watch PDF link annotation
    • http://tryplafond.xyz/esl_business_english_conversation24kju.pdfIn PDF document text
    • http://rodsfish.club/2736584002wvef8.pdfIn PDF document text
    • https://mapipuluzobeb.weebly.com/uploads/1/3/1/3/131398440/9829553.pdfIn PDF document text
    • https://cdn.sqhk.co/fejisedetu/H7hb5WK/assassin_s_creed_odyssey_shipwreck_cove_treasure_locations.pdfIn PDF document text
    • https://cdn.sqhk.co/lexebogefaj/ibGgdjc/lapotun.pdfIn PDF document text
    • https://cdn.sqhk.co/tamupoto/ijVhdZr/ralilujibeju.pdfIn PDF document text
    • https://tivubolo.weebly.com/uploads/1/3/1/8/131857038/pozutano-pidanowowax-tanidesok-raganedis.pdfIn PDF document text
    • http://weareanonymous.org/lekexitobodikadazolsz65y.pdfIn PDF document text
    • https://cdn.sqhk.co/doboketuzoj/Lgdzdhd/running_princess_2_game_play_online.pdfIn PDF document text
    • https://dusonomikeka.weebly.com/uploads/1/3/2/6/132695238/lokujof.pdfIn PDF document text
    • https://bexokibuki.weebly.com/uploads/1/3/2/3/132302940/vesoporujunif_zifetow.pdfIn PDF document text
    • https://vikerurinarifu.weebly.com/uploads/1/3/0/7/130776567/cb13eb18.pdfIn PDF document text
    • https://kelutatu.weebly.com/uploads/1/3/4/5/134521402/pubetux.pdfIn PDF document text
    • http://trysoda.pro/19888972001itm8l.pdfIn PDF document text
    • https://mujaxelixoduren.weebly.com/uploads/1/3/3/9/133997177/6a37051.pdfIn PDF document text
    • https://nugaruxiboxora.weebly.com/uploads/1/3/0/7/130738781/313279.pdfIn PDF document text
    • https://cdn.sqhk.co/basinasedu/asF2FPF/japevimup.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/d923547c-89f3-40e8-b611-68325573183a/smart_wristband_3_user_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1142f4e5-d83f-4b19-af4b-2ecd289b558a/are_ashton_drake_dolls_worth_the_money.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3f9c0d12-0c5d-4363-ada9-7300d72b3444/foxit_reader_serial_key.pdfIn PDF document text
    • https://s3.amazonaws.com/wovitiku/103880206.pdfIn PDF document text
    • https://s3.amazonaws.com/sowewazulejewi/logitech_g910_lighting_effects.pdfIn PDF document text
    • https://s3.amazonaws.com/guxosa/zavizegoti.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7a780526-dadf-44fa-a37e-76db6b8b3ebb/zumop.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/92a67a45-0b64-49d9-8445-61ad04ce1b34/chronicles_of_ancient_darkness_free_download.pdfIn PDF document text
    • https://s3.amazonaws.com/tejuvonixag/interior_designing_websites_templates_free.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001628a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1628A 9624 bytes
SHA-256: 749437d98e87bc5e201973c7a721828787785183d12707fac9b44e962a2e46aa
font_01_sfnt_off0001824f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1824F 5288 bytes
SHA-256: 077236ccd3fbfcbfb096c32f6891799dc483cbfd3f47522ff195905069016998
font_02_sfnt_off00019465.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x19465 14052 bytes
SHA-256: 4e196eed5000521fead2148ff65b3956396d528f3e0562cc14d258598c58f668