Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f09d35c9f9b677e…

MALICIOUS

PDF

69.2 KB Created: 2021-09-30 21:29:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-26
MD5: b466d99da02d10d8bfc76c89465834f2 SHA-1: 4446d25ae56892dd5dbeacbd9569cadf0e130ecd SHA-256: 4f09d35c9f9b677e9ac09c3755a7b7745fc8e17b86020cc3db6e7da2998d4bbc
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains numerous external links, many pointing to disposable domains, suggesting a link farm or redirection mechanism. While no scripts were explicitly extracted, the presence of external URIs and the nature of the heuristics indicate an attempt to direct the user to malicious content, likely for phishing or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9893

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kheops-so.fr/ckfinder/userfiles/files/49015569008.pdf In PDF document text
    • http://xlpe.net/Images_upload/files/xugokajojumepujana.pdfIn PDF document text
    • http://leeharringtonhomes.com/userfiles/file/remoduga.pdfIn PDF document text
    • http://unseenadventure.com/userfiles/file/68863257491.pdfIn PDF document text
    • https://eghamatsafar.ir/basefile/eghamatsafar/files/wusepefebonodirevariwa.pdfIn PDF document text
    • http://hennel.hu/sources/elemek/file/48999551892.pdfIn PDF document text
    • http://icbiz.ru/userfiles/file/ruzujovepojin.pdfIn PDF document text
    • https://bednidhitraders.com/userfiles/file/13376297657.pdfIn PDF document text
    • https://rmp-traueranzeigen.de/cms/files/ponekewoludekavutoke.pdfIn PDF document text
    • http://whuntex.info/userfiles/file/xewoniwowutirikeletar.pdfIn PDF document text
    • http://saatgaamkansarasamaj.com/admin/uploads/files/12848885792.pdfIn PDF document text
    • https://kohphanganhotelandtour.com/userfiles/file/nexepudazulixiworixugal.pdfIn PDF document text
    • https://candbco.com/ckfinder/userfiles/files/58903661646.pdfIn PDF document text
    • http://versobrokers.eu/userfiles/files/72570302034.pdfIn PDF document text
    • http://imdad-egypt.com/userfiles/file/72310703623.pdfIn PDF document text
    • https://onlinendttraining.com/files/8258817409.pdfIn PDF document text
    • https://auto-rujo.com/images-editor/file/gavofixuzaf.pdfIn PDF document text
    • http://csc0532.com/userfiles/file/20210920183615_z2shn7.pdfIn PDF document text
    • https://forkidsvietnam.vn/wp-content/plugins/super-forms/uploads/php/files/9alprfk3b18352000ujng3kgpp/fepijoduwef.pdfIn PDF document text
    • https://emartdeko.pl/galeria/file/54940920176.pdfIn PDF document text
    • https://asiarsolutions.com/userfiles/file/gipikujusivi.pdfIn PDF document text
    • http://awkontrakt.pl/ckfinder/userfiles/files/ruwubabufezakef.pdfIn PDF document text
    • http://pecsimutargygaleria.hu/files/file/gakisafebagiki.pdfIn PDF document text
    • http://vidol.nl/userfiles/file/kododofamowedevo.pdfIn PDF document text
    • http://buydecor.ru/uploads/files/96639936880.pdfIn PDF document text
    • https://markyatirim.com/resimler/files/fewojovudid.pdfIn PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/zMnd8XtcwSM/uplcv?utm_term=htc+one+m7+android+5PDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b1b1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB1B1 15044 bytes
SHA-256: 17d1df2049a1e07fc7fc1b2bb1b6bed1240237b7edfe61b0d73ef87d1b51c303
font_01_sfnt_off0000d795.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD795 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_02_sfnt_off0000efac.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEFAC 10492 bytes
SHA-256: 196c1c0764d87c5cd0f83006f175721869f862bffa2f98ef8ecc01da9b4cb1da