Malicious PDF — malware analysis report

Static analysis result for SHA-256 7751aada1f1731a5…

MALICIOUS

PDF

74.9 KB Created: 2021-03-10 07:32:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-22
MD5: 14998c6e90f8868502be59bd92ade010 SHA-1: ec239bbcb32fed8ae69ce4d178f73b496dee1d73 SHA-256: 7751aada1f1731a5bbf44b7883b6846dd577401849fd05c0ad7fb5ce6c08e33a
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, with one specifically identified as a link farm on disposable hosting, suggesting a phishing or malware distribution attempt. The ClamAV detection and ML classifier strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of a malicious document designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=how+to+draw+puppy+eyes PDF link annotation
    • https://nurafotupitu.weebly.com/uploads/1/3/4/4/134495453/455784d81f1c21.pdfIn PDF document text
    • http://wotidoteked.mywebcommunity.org/what_are_the_most_common_catholic_prayers.pdfIn PDF document text
    • https://pusuxefemaj.weebly.com/uploads/1/3/4/1/134108889/3854662.pdfIn PDF document text
    • http://leftoutclub.com/hemostasis_in_dentistryxmdwi.pdfIn PDF document text
    • https://lugexobamav.weebly.com/uploads/1/3/5/9/135965248/jubuxojovitojobuzafi.pdfIn PDF document text
    • http://silujokiz.mypressonline.com/homoeopathic_temperament.pdfIn PDF document text
    • https://sivaxawisebirim.weebly.com/uploads/1/3/1/4/131407763/rutolugamafidak.pdfIn PDF document text
    • http://rolorutebu.sportsontheweb.net/34406791985.pdfIn PDF document text
    • http://nout-prokat.website/judanafesufiludqmup.pdfIn PDF document text
    • http://itayoga.space/xejumitijurelifedabusupioiojo.pdfIn PDF document text
    • http://pupofikavize.iblogger.org/gobizo.pdfIn PDF document text
    • http://jukojadijomefar.medianewsonline.com/autocad_3d_commands_and_their_uses.pdfIn PDF document text
    • http://vofufime.mypressonline.com/utility_software_definition.pdfIn PDF document text
    • http://itclick.pro/wilderness_survival_guide_dnd_5edjyfn.pdfIn PDF document text
    • http://xugerovogubex.22web.org/juditagukuvarolisivu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/7b7f8175-9086-4e2c-b61b-3466d8e015e3/videojet_1520_excel_service_manual.pdfIn PDF document text
    • http://kitilogokufalu.atwebpages.com/emotional_guidance_scale_esther_hicks.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cda2336c-a266-40fc-923b-286a87fda190/81796667835.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6bfa3525-0f7a-4a13-94bd-a06813f426a7/ubuntu_linux_terminal_commands_cheat_sheet.pdfIn PDF document text
    • http://jatoxat.atwebpages.com/windows_batch_file_commands.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e47b179d-8a0c-4a12-b68a-2756458df00b/50_shades_of_grey_actor_interview.pdfIn PDF document text
    • http://nalejunubotuw.rf.gd/boss_gt_1000_4_cable_method.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/563486af-6bda-4f99-a7e2-73c48465231f/yamaha_htr_5540_specs.pdfIn PDF document text
    • http://pelebirepopo.onlinewebshop.net/argumentative_essay_structure.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e978.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE978 5076 bytes
SHA-256: e16fa886187fed0370f484b7944e1c50788f10b48b0986bdc072a4a46c717594
font_01_sfnt_off0000fadc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFADC 10464 bytes
SHA-256: 9d7a8d050be112dbe2d9c3b5d6bbabc0bb6c9dad07c73637286803ca7481dcdd