Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b14a51bee4794dd…

MALICIOUS

PDF

125.5 KB Created: 2021-04-07 07:55:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-26
MD5: 2070676c673d824c8a22ff9495c1bed6 SHA-1: c15108c47ba7cbedc950d897ce64704d1f8b3de7 SHA-256: 4b14a51bee4794ddb023250cae5eefd5efa7f51a22d59d218aa9d82cdb57e7a1
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, many of which point to disposable or unknown domains, suggesting a link farm or phishing attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, specifically identified as phishing. While no scripts were directly extracted, the PDF structure and embedded links are consistent with a phishing lure designed to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9986

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.jwico.com/sites/default/files/webform/71926652616.pdf In PDF document text
    • http://www.grotekeukens.be/sites/default/files/webform/gmawards2018/87706268510.pdfIn PDF document text
    • http://oaklandchildcare.org/sites/default/files/webform/85322732160.pdfIn PDF document text
    • https://www.natsihwa.org.au/sites/default/files/webform/zolevijovexoneda.pdfIn PDF document text
    • http://www.pbttphtk.gov.my/sites/default/files/webform/nolukaronedibikix.pdfIn PDF document text
    • http://www.muttypawsacademy.com/sites/default/files/webform/vaccines/95859103094.pdfIn PDF document text
    • https://www.mainephilanthropy.org/sites/default/files/49101071505.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/vopezupudatirarib.pdfIn PDF document text
    • https://www.mothercare.ro/sites/default/files/webform/resumes/jevosofotabotasif.pdfIn PDF document text
    • https://www.osgeurope.com/sites/osg-corporate.dev/files/webform/nutuzisujobipusife.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://feedproxy.google.com/~r/Uplcv/~3/GLLx1DTH0VQ/uplcv?utm_term=ainsi+parlait+zarathoustra+en+arabe+pdfPDF link annotation
    • https://www.healthdata.org/sites/default/files/resumes/sutuzosugogaw.pdfIn PDF document text
    • https://community.princeton.edu/system/files/webform/42655509772.pdfIn PDF document text
    • https://drones.princeton.edu/system/files/webform/janewif.pdfIn PDF document text
    • https://printandmail.princeton.edu/system/files/webform/31356988355.pdfIn PDF document text
    • https://campusrec.princeton.edu/system/files/webform/putiwokareviwe.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off0001a680.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1A680 26072 bytes
SHA-256: 5b30f9f8dc9d772daf99abc0c2d9879672d8d0e3eff9f71726b40278df0fcfcc
font_00_sfnt_off0000f76f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF76F 26288 bytes
SHA-256: 1d3596a2da0d68a59c26bc840606e84efb60bb4ce5c3acc0121951a3640e39f5
font_01_sfnt_off00014aa1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14AA1 5308 bytes
SHA-256: 422afd28bc96982919d08c4fb2319cffc750bf9788289cbec387bf8bff5ac553
font_02_sfnt_off00015ca0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15CA0 6068 bytes
SHA-256: 58b4873d33ac9fffaf45ed1a2312b8eb5fadf3b067e77f8cfe9e87095f6a7717
font_03_sfnt_off00016c51.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16C51 20200 bytes
SHA-256: 9471ce0f00b6b39658f277fcd16965195f61f37878539d38b37a70d56f3fc6ac
font_05_sfnt_off0001d916.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D916 3528 bytes
SHA-256: 0b89479afec2f368a43ca64ad8779ebb9573dd2d7ac817c6b25c83891722010f