Malicious PDF — malware analysis report

Static analysis result for SHA-256 474fab7f99e88cdc…

MALICIOUS

PDF

75.6 KB Created: 2021-05-23 13:04:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-13
MD5: 96cb0970b00b294c453a2f13880021f0 SHA-1: 2d5eee77709742abe73718e7db5d5106203510af SHA-256: 474fab7f99e88cdceac8e3b7b5c7f011e9dc5b9489a72e438b795b58d6aa51e1
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF contains a significant number of external links, many of which point to a redirector URL (https://baarspo.ru/strik?utm_term=lg+k10+2017+android+8). This heuristic, combined with ML classification and ClamAV detection, strongly suggests malicious intent. The document body is heavily obfuscated, but the presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic indicate a likely attempt to drive traffic to malicious sites for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/strik?utm_term=lg+k10+2017+android+8 PDF link annotation
    • https://gapotijaj.weebly.com/uploads/1/3/1/3/131383657/cb64244.pdfIn PDF document text
    • https://pawudovavumub.weebly.com/uploads/1/3/1/4/131411600/93340c5a.pdfIn PDF document text
    • https://regifevadep.weebly.com/uploads/1/3/4/4/134476302/juditipulupe.pdfIn PDF document text
    • https://febadezupuwile.weebly.com/uploads/1/3/1/0/131071278/6588150.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/4a3c4e51-610d-4393-8426-518b75b7d5ce/joxifijo.pdfIn PDF document text
    • https://s3.amazonaws.com/sabegokek/kenmore_elite_dishwasher_side_mounting_brackets.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/77143be9-d925-4d1c-a983-98b0580531b7/41800539735.pdfIn PDF document text
    • https://s3.amazonaws.com/zalisujezajaje/how_to_find_a_rental_apartment.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3d5aeac4-aa72-42a1-9a6a-9e46077181a4/gizofo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1e7a4707-4000-4e67-b59b-27a25b7ef07e/rinegejokusamopisujibag.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2c61b12f-7691-4fce-a330-e7a8c4070963/49020806494.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c4e86569-821e-406e-bd9a-58d747d385d8/ruvapafufonetosok.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/59f8675e-f89e-4cae-b97b-ce3f6b87c397/how_do_i_find_old_satellite_images_on_google_maps.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c329d9e5-ef60-4e78-b53d-cb1416a07612/what_is_an_example_of_a_logo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e965e2bb-67f3-41de-bfc6-92e085ea79cd/stock_market_books_by_black_authors.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c0dd78f9-8bf5-4f5c-96fb-a35f4672792e/mepenudubixajabuxobako.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9135f3db-6672-42f3-b263-81ba98abc128/shakespeare_insults_calendar.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/491f3b6e-93aa-4432-8e10-0ed33d96c14f/does_google_play_books_cost_money.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3aff58db-dbe0-400a-9831-1b09ade708f2/laridedizore.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c745fdf6-90f2-4864-8a14-fccc5c3755f2/7951830526.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/44333226-4ead-451f-b593-8ae5c2cfb94c/54327547478.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c49261e0-e779-4a1c-a70c-4f1f06599ad1/14610886126.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d3d2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD3D2 5388 bytes
SHA-256: 8efd3d033b1ef81a2a97b8c48604d57fd5c886abb07ce235bfcc53d230360195
font_01_sfnt_off0000e647.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE647 10428 bytes
SHA-256: bcdd9872fcfb6cf00fb5a9b537a517539da385886dcab93ffc42ac218705aabe
font_02_sfnt_off00010a2e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A2E 16088 bytes
SHA-256: 6fded02eca0f92369f39543261631dc0570ae7f1b5bcb2281e5b286133732c81