Malicious PDF — malware analysis report

Static analysis result for SHA-256 40ac88aa7d791583…

MALICIOUS

PDF

161.8 KB Created: 2021-05-10 06:39:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-20
MD5: 801368fa93382238d9a7cff1de0eb26e SHA-1: c935071a63fd8a9a8d07d7ad1f76adb4f12ee774 SHA-256: 40ac88aa7d791583418298f4db37e7c52302decc86b8bb0cf312cf88537af244
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs and is flagged by ClamAV as Pdf.Phishing.Trojan. The ML classifier also indicates maliciousness. The document body, though heavily obfuscated, appears to be a lure related to a search query, directing users to external sites that are likely part of a phishing or malware distribution chain. The presence of numerous disposable domains and link farms suggests a campaign focused on redirecting users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7706

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/strik?utm_term=how+do+you+say+sunrise+in+japanese PDF link annotation
    • https://cdn.sqhk.co/befozaxulot/biaigU0/zusasozudozoxebome.pdfIn PDF document text
    • https://wezefumuge.weebly.com/uploads/1/3/4/6/134614004/3630897.pdfIn PDF document text
    • https://cdn.sqhk.co/pefisemise/uii5sja/90439145842.pdfIn PDF document text
    • https://cdn.sqhk.co/sifapudoxig/jajdivJ/80594909228.pdfIn PDF document text
    • https://wovitinukid.weebly.com/uploads/1/3/4/3/134372120/c76694df19.pdfIn PDF document text
    • https://tabikajodunel.weebly.com/uploads/1/3/0/7/130739544/ritagiwejidofo_ledab.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4471455/normal_60393e585182b.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4367938/normal_5ffd9e392bdd7.pdfIn PDF document text
    • http://picsonair.com/viewsonic_pjd5155_reviewfyvsn.pdfIn PDF document text
    • https://nasesugafod.weebly.com/uploads/1/3/5/3/135387958/fozovijowisanenilav.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367922/normal_60651af0713a3.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4454665/normal_6002c092c37fe.pdfIn PDF document text
    • https://dotaterezisal.weebly.com/uploads/1/3/4/7/134771172/dikemuzu.pdfIn PDF document text
    • http://thelait.pro/system_design_definitionhr93c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4501495/normal_6064591a30761.pdfIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/9714feb2-9cd6-40c3-aa9f-48daff193c49/33387453551.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bae6167f-f7a8-4bff-979b-61de5ede4250/midemixujevatokubovezuz.pdfIn PDF document text
    • https://s3.amazonaws.com/nefagolom/kitchen_trolley_designs_catalogue.pdfIn PDF document text
    • https://s3.amazonaws.com/fajonubinomeder/dnd_5e_best_druid_feats.pdfIn PDF document text
    • https://s3.amazonaws.com/tokit/zikidepoxivavogidifin.pdfIn PDF document text
    • https://s3.amazonaws.com/lakujusitejojet/17746370978.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • http://www.gnu.org/licenses/lgpl.htmlRegularDanhHongIn PDF document text
    • http://www.geocities.com/dnhhngIn PDF document text
    • http://sinhala.sourceforge.net/In PDF document text
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
    • http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off0001d15d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1D15D 2980 bytes
SHA-256: fe87f82683a901406bcd5daa47473cbce500b6a02088f6e7b5553cdb4e03da2a
font_00_sfnt_off00013553.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13553 7588 bytes
SHA-256: b8d777aa4f70d49844326a6c9547fc255dfaf3b66696f94758877f0ea7f9581a
font_01_sfnt_off000148b3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x148B3 30392 bytes
SHA-256: e658f42b565f913164bb70b1407ad6c242e17e404614820a0a4e4011fce54eb5
font_02_sfnt_off0001a732.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1A732 4956 bytes
SHA-256: f5df3593c82f0458c280924e7580fdb45140fc7ba80f5fef4332647eaaca9f8a
font_03_sfnt_off0001b81d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1B81D 2864 bytes
SHA-256: be71cdad09c9ac77e9fd1ffc541529a72f9c8de4dc82219acf93f5b829ab869b
font_04_sfnt_off0001c3c9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C3C9 4256 bytes
SHA-256: 5de04deb201f913092cb52e1199ed443aaa073ca8af68f960186c7a3623563d7
font_06_sfnt_off0001dd17.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1DD17 4496 bytes
SHA-256: 5bdbab0ca9d0d4b02dfd0843e4c1ba994f11c2eea481cf10eda30974317247a8
font_07_sfnt_off0001eab1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1EAB1 4160 bytes
SHA-256: b02a00e032e903bc7c35a761f26b3febd44ccae1e94d37b83f1538061b170bfb
font_08_sfnt_off0001f947.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1F947 6412 bytes
SHA-256: 7132cbccffb168629b71222add5b1bcfbe96b8ec60af4bc22766be27ef6ae385
font_09_sfnt_off00020a53.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x20A53 18704 bytes
SHA-256: 981e2c7d2a01ff00f5b6dc0c703392997649717e21e7be14a44cea7f80d67b47
font_10_sfnt_off00023f91.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x23F91 18700 bytes
SHA-256: dc665d9926e03541aa130f69fb0fe9da58467e03b248c0b04f945f98ab2c771e
font_11_sfnt_off00025d4c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x25D4C 4324 bytes
SHA-256: 7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
font_12_sfnt_off00026b56.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x26B56 2564 bytes
SHA-256: 82f51d2131cd6d96a88058de9f9731ea56380c7df33839b50b9f9f6549a9bef1