Malicious PDF — malware analysis report

Static analysis result for SHA-256 6428f334eaa3da91…

MALICIOUS

PDF

87.3 KB Created: 2021-03-17 22:23:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-13
MD5: 1af7e54f4d90d9525471d3ef1f2fe4f1 SHA-1: f76a057c16d8ae9dbf574933d3482e66df4a3ba4 SHA-256: 6428f334eaa3da9124d7256d6a5f2872f441a0eed4fc3c254a09e5194db7cb39
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file contains a large number of external links, many hosted on disposable domains, indicating a link farm or SEO spam campaign. The ClamAV detection and ML classifier strongly suggest malicious intent, likely phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and numerous external URIs are indicative of techniques used to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/award?keyword=nrega+job+card+application+form+in+bengali+pdf PDF link annotation
    • https://jokikisiva.weebly.com/uploads/1/3/0/8/130873994/65bc0b2cad3e.pdfIn PDF document text
    • https://cdn.sqhk.co/giruzegovu/cjhLdje/buy_real_instagram_followers_country_targeted.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451353/normal_60233c1da84ee.pdfIn PDF document text
    • https://tigewatujuw.weebly.com/uploads/1/3/0/7/130738543/7132712.pdfIn PDF document text
    • https://cdn.sqhk.co/xetokive/gjmbBjg/2_player_horror_games_steam.pdfIn PDF document text
    • https://cdn.sqhk.co/devisofage/ijf5yhi/16031812925.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4402711/normal_5fd0662ecfd2c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://lesiterifok.epizy.com/bo4_aimbot_xbox_one.pdfIn PDF document text
    • https://27158da8-170d-48ca-a528-b8ced62fe517.filesusr.com/ugd/9fc8c3_5f7eecf824374465b2d87b4c2de72e47.pdf?index=trueIn PDF document text
    • http://ramenejepom.rf.gd/jazzy_select_6_ultra_parts.pdfIn PDF document text
    • https://0778d94d-b67d-49c3-8f6f-43f52d6edec9.filesusr.com/ugd/b85eb0_4d2418cb1dbe4d89ba6491b002d029a9.pdf?index=trueIn PDF document text
    • http://susupufewowe.epizy.com/how_to_use_dremel_3000_to_cut_wood.pdfIn PDF document text
    • http://fazafof.rf.gd/one_summers_day_piano.pdfIn PDF document text
    • http://miwunomo.epizy.com/13457344673.pdfIn PDF document text
    • https://7915398d-c9c2-4241-abdb-40cf742e4b8d.filesusr.com/ugd/d4df0f_fd3a598aeb4c4f369ae9a24b40e3f2d5.pdf?index=trueIn PDF document text
    • https://c7f0abc7-d23b-482d-bd16-0771495bb668.filesusr.com/ugd/bb13a2_460ce5b7d30644b7bf326524ea502448.pdf?index=trueIn PDF document text
    • https://75a697d3-84f0-44cf-bab9-f05e37020c50.filesusr.com/ugd/7c3584_445ad7ce96914811bff7df2cac0c932d.pdf?index=trueIn PDF document text
    • http://mukokulag.epizy.com/96591720719.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e479.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE479 5268 bytes
SHA-256: 329185fde03e508f6f97e5154a50ed92c878624a25d05a974565f98bcbbff77d
font_01_sfnt_off0000f64b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF64B 10884 bytes
SHA-256: de4d1f079b1d45fdfc3185aafd9142b94136a68f8328ef4623330e132e6371f5
font_02_sfnt_off00011b8f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11B8F 16172 bytes
SHA-256: 461a1578f80084b2f2ca998a6e716936969cc9b33b2976d66eaaa57f6abee57a
font_03_sfnt_off000130ac.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x130AC 4324 bytes
SHA-256: 1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
font_04_sfnt_off00013eac.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13EAC 4244 bytes
SHA-256: 5c6ed6109a2a9cca57069fb9b40d0b60a42676f89c46331b5e93c7a6e9bd4530