Malicious PDF — malware analysis report

Static analysis result for SHA-256 3502c683bc786ffb…

MALICIOUS

PDF

94.0 KB Created: 2021-04-29 14:40:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: 81a62a45f309d0adc71c664b4942c2b5 SHA-1: cb2c6dfacf57a4d38b1ce28afd86319c08e7b1a7 SHA-256: 3502c683bc786ffbe269d8242ee2636db961d133a7ca0ce67f5ee1984c1138d0
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links that redirect to known malicious infrastructure, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The presence of a 'Download Now' lure further supports a phishing or scam attempt. While no scripts were directly extracted, the ML classifier and ClamAV detection strongly suggest malicious intent, likely involving a downloader or redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=sherlock+holmes+book+in+sinhala In PDF document text
    • https://cdn.sqhk.co/jokawefezo/Jxje249/josegokenunilapakulovus.pdfIn PDF document text
    • https://cdn.sqhk.co/rirelolut/ngidhgy/kodiak_bear_bites_where_to_buy.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370265/normal_6011a323944ba.pdfIn PDF document text
    • http://duvejiwuxikon.getenjoyment.net/mekirexutimibitugemetug.pdfIn PDF document text
    • http://fegokodelaxen.scienceontheweb.net/black_s_law_dictionary_8th_edition.pdfIn PDF document text
    • https://cdn.sqhk.co/kilalovuge/hijahjb/how_to_draw_cute_cartoon_animals_videos.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4446283/normal_5fedb2949b84e.pdfIn PDF document text
    • https://cdn.sqhk.co/nobipajami/jhjjVkj/5s_daily_checklist_examples.pdfIn PDF document text
    • http://ver-alex.website/habitat_acropora_formosa6t7q6.pdfIn PDF document text
    • https://cdn.sqhk.co/ranofakon/ieQhahg/paypal_customer_service_usa_email.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365546/normal_606a4833661f1.pdfIn PDF document text
    • https://cdn.sqhk.co/wazafanez/ia5Tjah/73502642998.pdfIn PDF document text
    • https://cdn.sqhk.co/vidikusupegu/QihKb7J/wet_sounds_sw_808_review.pdfIn PDF document text
    • http://ponemofetu.scienceontheweb.net/xidoxetubusowupezep.pdfIn PDF document text
    • http://toreret.scienceontheweb.net/16711172184.pdfIn PDF document text
    • http://reawolt.online/vivitar_mini_digital_camera_pictures6mxrx.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/8751b8ce-8ef7-4d66-89e3-84a586d4e73c/10706721205.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/83d51fb8-5275-4866-9ca9-f6c28ce3e774/56289629196.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/458082e2-1e30-4ce9-8535-2cbf0607909c/how_much_does_the_dragon_ball_z_kakarot_dlc_cost.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8064d5ab-def4-4b0c-89c1-4a30c6d15ecd/mr._coffee_cafe_barista_espresso_and_cappuccino_maker_with_milk_steamer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/278190ad-5b3d-4274-9095-a4c6bc76c26f/hands_of_light_barbara_brennan.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://sinhala.sourceforge.net/In PDF document text
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
    • http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5f5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF5F5 5344 bytes
SHA-256: de193a085ce92e4ad90e936e03a2c56a94a47d7468158515a206f403404ad994
font_01_sfnt_off000107b5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x107B5 24964 bytes
SHA-256: c7c42f7077c64b2132d52a133a073d406b2d513a3d1282ca7c4f53a411bc56f7
font_02_sfnt_off00014401.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14401 11152 bytes
SHA-256: ac0a9c30d9f880d912560ed75a04e11aecabe0adf72d24442f830064c27a7627