Malicious PDF — malware analysis report

Static analysis result for SHA-256 704794b24a8cd3f1…

MALICIOUS

PDF

101.7 KB Created: 2021-04-02 16:15:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: d8d8c6a5e2ecd522cc78c89d17bcb8d6 SHA-1: a963df3cb81763e0ececfb9f991a140e7517fc68 SHA-256: 704794b24a8cd3f1c354047ffa8325f5b84dcebf51902192e79f5b0de4f6b2ed
166 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains numerous embedded URLs, many of which point to disposable hosting. The ML classifier and ClamAV detection strongly indicate malicious intent. The presence of external URIs and the 'Password-protected archive lure' heuristic suggest the document is designed to trick users into downloading further malicious content or visiting phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9976

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=most+op+script+roblox PDF link annotation
    • http://beduzevitugok.mypressonline.com/guledixemudotugunavid.pdfIn PDF document text
    • http://larekew.mywebcommunity.org/gym_program_to_lose_weight.pdfIn PDF document text
    • http://dinewegivogofe.mygamesonline.org/48305503935.pdfIn PDF document text
    • http://mosasekoz.22web.org/word_order_exercises_with_answers.pdfIn PDF document text
    • http://viwudij.22web.org/77139412093.pdfIn PDF document text
    • https://cdn.sqhk.co/xadeviro/8UBWifu/nazolidebunowiwodixux.pdfIn PDF document text
    • http://paxezot.getenjoyment.net/libro_para_aprender_a_tocar_guitarra_clasica.pdfIn PDF document text
    • https://cdn.sqhk.co/jawosuzexe/ljjTL9f/realistic_off_road_extreme_truck_driving_simulator_3d.pdfIn PDF document text
    • https://cdn.sqhk.co/pinuwinepasu/EVhgjfD/1197460516.pdfIn PDF document text
    • https://cdn.sqhk.co/moturira/dNjbBtF/251473700.pdfIn PDF document text
    • https://cdn.sqhk.co/lulaxujik/qljcRhd/mopumebilotuke.pdfIn PDF document text
    • https://cdn.sqhk.co/nozesinipi/fggifOA/musugisarejimipodapuzar.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://bilisedutave.myartsonline.com/high_level_caselet_di.pdfIn PDF document text
    • http://jesebikalag.epizy.com/rusekobode.pdfIn PDF document text
    • https://de99934f-f465-4d69-af5e-14f317c0a7c6.filesusr.com/ugd/4fea5c_14f2d6bc6f424387b8c13d45684f3d26.pdf?index=trueIn PDF document text
    • http://gibopaxoga.epizy.com/huskee_24_snowblower.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f9005c93-bece-41a4-aca0-a79d39cdee20/42797066190.pdfIn PDF document text
    • https://c0a42e0f-4cce-4e1b-84a6-2a5440198d67.filesusr.com/ugd/440b6d_d41c4d04b3314d1d95144b8e56b82703.pdf?index=trueIn PDF document text
    • https://8772a198-af03-49ef-8724-5feb7546cb8a.filesusr.com/ugd/436f04_cf8e23bfcb9f44bea1e87b755a565b71.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a87383a-ec5e-44a7-9b4b-a15d1b106f70/67344661453.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/62f4db72-44a0-440d-96cc-1cfcfd1e9c36/julogonapenofanesata.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ce76cd46-0ab9-4aeb-94c8-56ae74d81dc3/dometic_9100_awning_parts_diagram.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/383316ab-1cd2-4a79-b8da-7cb86b055a6c/zelarukigen.pdfIn PDF document text
    • http://verejixufitoge.rf.gd/button_color_android_xml.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012410.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12410 4928 bytes
SHA-256: 3d3b8779b5a1565d2c6c30f777859033e9a07aad71283ea0561fd14849c05f32
font_01_sfnt_off000134ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x134EC 4592 bytes
SHA-256: 20a9df4623b369554da27eb568e484f73d72ee56bba66de0b8b90bd1a0883ac9
font_02_sfnt_off0001465b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1465B 14424 bytes
SHA-256: 1928efdd095c0104bbcd68120d78eb47be3e2eff0d4015036284b31e7d01db90
font_03_sfnt_off000172fb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x172FB 16340 bytes
SHA-256: 3f76e9b184ae7262c7f9a85e6b5d457b14ab79fd4c89c5d9e590ad7fd4806a87