Malicious PDF — malware analysis report

Static analysis result for SHA-256 4eaf91f4cdf039a7…

MALICIOUS

PDF

86.0 KB Created: 2021-03-27 11:20:13 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 206bb13665f14aa5a726b15af7e77839 SHA-1: 9f01b636298da36de6750d4d4f3e816bc0aa905f SHA-256: 4eaf91f4cdf039a73ec0fa5ab46c8f1227e9ae1a9bcbf32afff85acb344142a8
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, indicating a phishing or trojan payload. It contains numerous embedded URLs, with one pointing to 'golowaki.ru', suggesting it's part of a link farm designed to redirect users to malicious content. The document's structure and embedded links align with common phishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/award?keyword=goldman+cecil+medicine+pdf
    • https://zuvitapud.weebly.com/uploads/1/3/1/4/131406427/xunanesadibes.pdf
    • https://cdn.sqhk.co/xorilulog/hapAjcG/fruit_slash_free_download.pdf
    • http://lejidakoxinetog.mywebcommunity.org/kodakumetut.pdf
    • https://cdn.sqhk.co/xobakidanav/ieihY4X/naxobefepu.pdf
    • http://gosofejabe.iblogger.org/70177639492.pdf
    • http://xojuxelase.medianewsonline.com/can_t_take_my_eyes_off_you_piano_sheet.pdf
    • https://cdn.sqhk.co/pidikuso/e98id43/faily_brakes_game_download.pdf
    • http://bewugexujiz.iblogger.org/affidavit_format_of_marriage_registration.pdf
    • https://bexusisase.weebly.com/uploads/1/3/4/5/134596812/tivitodudomido.pdf
    • http://gasurorir.sportsontheweb.net/arabic_tamil_dictionary.pdf
    • http://vakiduweg.mygamesonline.org/viktor_frankl_mans_search_for_meaning.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/3734a339-9660-4518-8725-15bdccf0ad27/is_there_sugar_in_dunkin_donuts_french_vanilla_coffee.pdf
    • http://peguretunemidom.rf.gd/free_training_checklist_template_word.pdf
    • https://uploads.strikinglycdn.com/files/c7a13be6-cddd-4d0d-9dde-c676a94b781a/how_accurate_is_the_cva_wolf.pdf
    • https://uploads.strikinglycdn.com/files/7e4f8d35-d930-486b-bc26-ef58a8439828/riser.pdf
    • http://dinilemave.epizy.com/maggie_rogers_alaska_piano_sheet_music.pdf
    • https://f8b57e9d-e272-4783-b6f5-6420e6b93425.filesusr.com/ugd/886b73_d532c8043bba4ac982dd225137975350.pdf?index=true
    • https://538d8494-0c7d-401a-b890-0485f6bc7bca.filesusr.com/ugd/29c71c_4a644aa7fa614698b2e1535168ad4e08.pdf?index=true
    • https://uploads.strikinglycdn.com/files/79f88a12-2c8b-46de-9a10-af590ba1b1e6/html_table_cellspacing_css.pdf
    • https://uploads.strikinglycdn.com/files/695acd4a-edbd-42fb-b56c-610129133227/dapilekusosenosupivu.pdf
    • https://1f571a09-6495-4108-bd1a-9715deae29b5.filesusr.com/ugd/b0bf26_f4d9ebe3e25046538de7031b747ace94.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000112a9.bin
f3ecc7898fc51c104f2f09c7fcae0a8e2cadb4544628d291e6725bdfe3aa718d
pdf-font-stream PDF embedded font (sfnt) at offset 0x112A9 5056 bytes
font_01_sfnt_off000123d0.bin
b724ab04b25e673c86a6ce6a7ce066c3deb01c00bb361c39c1e77d5db52226bd
pdf-font-stream PDF embedded font (sfnt) at offset 0x123D0 11556 bytes