Malicious PDF — malware analysis report

Static analysis result for SHA-256 488fb80c28e10499…

MALICIOUS

PDF

120.7 KB Created: 2021-02-14 02:49:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: 9b2bd5491f499d00c3192dc69a7c1130 SHA-1: 73d519d70418771ffd878c9945ba95f9e2a12d56 SHA-256: 488fb80c28e104993ee69d519fbac18f9887fa709c90b191d3a809b8115337c6
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The ML classifier and PDF heuristics strongly indicate malicious intent. The document contains numerous embedded URLs, many pointing to disposable domains, suggesting a link farm or phishing lure. The presence of 'utm_term' in one URL further supports a phishing or spamming campaign. No scripts were extracted, but the overall structure and URL distribution point to a malicious PDF designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/123?utm_term=tv+guide+bellingham+wa PDF link annotation
    • http://jujaxapuwuravof.iblogger.org/zezavamila.pdfIn PDF document text
    • http://wukosemat.22web.org/baxi_megaflo_boiler_manual.pdfIn PDF document text
    • https://wutejaguruloz.weebly.com/uploads/1/3/1/8/131871665/2583243.pdfIn PDF document text
    • https://danegatazi.weebly.com/uploads/1/3/0/7/130776269/9580645.pdfIn PDF document text
    • http://all-system7.club/datakazeyc143.pdfIn PDF document text
    • http://epipog.com/naduzamifefixn2zeq.pdfIn PDF document text
    • https://sufudoni.weebly.com/uploads/1/3/4/8/134853368/warekuxun-nizijamubud.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4393761/normal_5feb1cada38c5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4475863/normal_60242af88f993.pdfIn PDF document text
    • http://prod-fruit.space/49633141494gs5y0.pdfIn PDF document text
    • http://on-arenas.com/59391441788yh1i4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4410714/normal_5fdc5a9d286c4.pdfIn PDF document text
    • http://mif-smeh.space/pesigemavirunuzakemevevoyrkl1.pdfIn PDF document text
    • https://tilemutafadat.weebly.com/uploads/1/3/1/8/131856023/8284595f79c02.pdfIn PDF document text
    • https://ponebivilu.weebly.com/uploads/1/3/4/5/134505494/582b9de2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4452217/normal_60271fe12a3c6.pdfIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://tosakiviga.rf.gd/whatsapp_for_windows_vista_home_basic.pdfIn PDF document text
    • http://mimonutemabase.epizy.com/cardigan_form_di_nam.pdfIn PDF document text
    • https://s3.amazonaws.com/papuja/lalunajulapugibisem.pdfIn PDF document text
    • http://xalovizavana.rf.gd/75169672953.pdfIn PDF document text
    • https://s3.amazonaws.com/jijumupade/letter_s_jolly_phonics_worksheet.pdfIn PDF document text
    • https://s3.amazonaws.com/rivazixexuguri/lawimosewadifiz.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00017b59.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x17B59 18452 bytes
SHA-256: bfca5b476350e399b286381424c93559c77bf296f44ecf521f4391a8ac456b78
font_00_sfnt_off000169bf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x169BF 5204 bytes
SHA-256: b85c14baad001c8249b8f2e423d3fe01e925a10060d44280475233383b2be422
font_02_sfnt_off0001acad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1ACAD 12700 bytes
SHA-256: 9e3dd8a7ac91f517f4d5a94c2279aa409f477b4ee7c6924a615d65642226cfce