Malicious PDF — malware analysis report

Static analysis result for SHA-256 629114b627d7c1d6…

MALICIOUS

PDF

90.5 KB Created: 2021-04-02 11:23:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-02
MD5: 90f7dc3b11b99ec6aa7b11622033e321 SHA-1: ebacf7535d03c86675df4fdc30a0e7a8965d8b2d SHA-256: 629114b627d7c1d6300efcdb705dd05f595985b2c9e86c061032c2e87965d4f6
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous embedded URLs, many of which point to disposable hosting and are likely part of a link farm designed to redirect users. The ML classifier and ClamAV detection strongly indicate malicious intent, specifically phishing. The document body, though heavily obfuscated, appears to be a lure related to search queries, aiming to drive traffic to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=what+are+the+major+theories+of+emotion PDF link annotation
    • https://mubisajapesufu.weebly.com/uploads/1/3/4/6/134620746/kuvizuturipab.pdfIn PDF document text
    • http://qrettalq.online/suridavumakaqzejg.pdfIn PDF document text
    • http://ryduslim.website/lobewabiwisixutajuwader1s02.pdfIn PDF document text
    • http://istra-backwater.ru/kumudavixelozisokodomajfws6.pdfIn PDF document text
    • http://kartaidatodemeleri.com/how_to_clean_a_honda_lawn_mower_carburetorpgepj.pdfIn PDF document text
    • http://verifiedbadges-form.com/4437465987eo7r8.pdfIn PDF document text
    • http://uscarinsurance.info/netgear_dg834g_instruction_manualb25s5.pdfIn PDF document text
    • https://soruxepamoni.weebly.com/uploads/1/3/5/9/135992355/sagajoxojesib.pdfIn PDF document text
    • http://summ-green.fun/dd_adventurers_league_season_1tm8gd.pdfIn PDF document text
    • http://negozio50sconto.info/mufujajg5bs6.pdfIn PDF document text
    • http://belepebo.mywebcommunity.org/rejinanunepadonir.pdfIn PDF document text
    • http://siondez.ru/3537955477obpsh.pdfIn PDF document text
    • http://fullstacket.online/dedufeloxoxewuyfhd7.pdfIn PDF document text
    • http://fivadoguna.medianewsonline.com/cross_sectional_anatomy_of_brain.pdfIn PDF document text
    • http://profyhouse.ru/riwijevotumimikulr4zh.pdfIn PDF document text
    • http://makebugobiwuka.mypressonline.com/nakogekorexekur.pdfIn PDF document text
    • http://boothattendant.com/la_biblia_en_audio_gratis_para_celulares1gzec.pdfIn PDF document text
    • http://intereriia.com/donaxolez9id81.pdfIn PDF document text
    • https://gulezawajure.weebly.com/uploads/1/3/1/8/131858287/a40bfc2ff50d7d.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://46b09160-81f9-4cb3-9cca-f7b5b0c0229e.filesusr.com/ugd/179cc6_f9c69ddc8f5c4b5e913ae2e862f0d8d8.pdf?index=trueIn PDF document text
    • http://popofisofol.myartsonline.com/45304330564.pdfIn PDF document text
    • https://e50eee24-2d95-422d-8083-6f618d95927b.filesusr.com/ugd/594ae5_a222a2dd40d24c168b30e86426b6c0c2.pdf?index=trueIn PDF document text
    • https://41c240d9-b4af-4f88-8fa4-2a41cce3a287.filesusr.com/ugd/01bc73_f28b14de9bff4c7e83a47cacb1653f3a.pdf?index=trueIn PDF document text
    • https://b9a4c3d6-4ccf-4d04-9b0f-c2e9c357e15d.filesusr.com/ugd/e5cbe5_782ca4c4bb1e41ad97c334962299560a.pdf?index=trueIn PDF document text
    • https://8d90b851-447f-4cfc-ac95-1e867b71b983.filesusr.com/ugd/b371d9_5995e0c4471b40b09aa3505a487c58b4.pdf?index=trueIn PDF document text
    • http://japinoxizidunub.myartsonline.com/how_to_replace_trimmer_head_echo_srm-210.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012784.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12784 5064 bytes
SHA-256: db22e544f35a5e9dfb59aa9d9f7dd32ce7361df519b60f60957160c54aac4bde
font_01_sfnt_off000138a0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x138A0 10692 bytes
SHA-256: cedbaa74b940c5fe102b2c340c1862d869e5aec1825ddd7981ca39d9d85c3bbd