Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a22f63cc9bbf24d…

MALICIOUS

PDF

78.6 KB Created: 2021-03-15 00:33:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-17
MD5: 04966487eecd6001b1d88456ce7270cb SHA-1: 114e3a576db9a68bc971dfa513b12500f407a453 SHA-256: 7a22f63cc9bbf24d61aadd8f9f5ae3ae80b38b9da1abac5b1d35f5cd22f68fea
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains numerous embedded URLs, many pointing to disposable domains, suggesting a link farm designed to redirect users to malicious sites. The presence of external URIs and the 'PDF_SEO_DISPOSABLE_LINK_FARM' heuristic indicate a strong intent to host or link to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9957

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/award?keyword=cumulative+distribution+function+pdf+relationship PDF link annotation
    • http://wusokamojifel.scienceontheweb.net/direccin_de_sanidad_polica_nacional.pdfIn PDF document text
    • http://marafonsport.site/buvogiwjxpg.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4422914/normal_601df37af12cf.pdfIn PDF document text
    • http://kinorio5.xyz/arena_of_valor_switchfp2t0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4477138/normal_5fee8e49d3e62.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4476140/normal_5ff685891c0ac.pdfIn PDF document text
    • http://gapijet.scienceontheweb.net/what_does_pop_culture_mean_today.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4373240/normal_60154d53577ef.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4371269/normal_603e8185a132f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4423460/normal_601b331950343.pdfIn PDF document text
    • http://vagoneviwesum.66ghz.com/chestnut_grove_uniform_policy.pdfIn PDF document text
    • http://jofarofuwudeveb.66ghz.com/printable_attendance_sheet_for_sunday_school.pdfIn PDF document text
    • http://lukisasore.mywebcommunity.org/grade_5_maths_worksheets_south_africa.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4482228/normal_6024ab16aad46.pdfIn PDF document text
    • http://birjand.design/50436543636tc82a.pdfIn PDF document text
    • http://kotodagojaf.iblogger.org/chennai_airport_taxi_bill_format.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4365553/normal_600278d5cedc0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4480412/normal_5fdbafe9883b6.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4419826/normal_60101306c3eef.pdfIn PDF document text
    • http://ganitigusawev.mygamesonline.org/math_10_module_unit_2.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://8a833fea-7c9a-4d2e-a5a7-d3590f42a3e5.filesusr.com/ugd/9aab09_2e92bea8c4ca41059108c566811288c1.pdf?index=trueIn PDF document text
    • https://044ec7df-721b-4788-b209-87474a3fcb06.filesusr.com/ugd/60ffa2_9bd49184bf484001a454c6d9f1800b15.pdf?index=trueIn PDF document text
    • http://dokudaruriwiv.atwebpages.com/mexutizilolin.pdfIn PDF document text
    • https://f64a1a0a-debf-4843-a838-a34c0cae0f4a.filesusr.com/ugd/89602e_b52737deccf3429891847dbb771ec3a0.pdf?index=trueIn PDF document text
    • https://77da94c0-0f0a-445b-87af-e489a0b5ef66.filesusr.com/ugd/db1da1_86152e0b3b0a425393c3ce140176a450.pdf?index=trueIn PDF document text
    • https://976edc35-935c-46de-9e6e-e225dbc25668.filesusr.com/ugd/0829d8_9e2cdde8b4204359a6ab898912b3418f.pdf?index=trueIn PDF document text
    • http://peragodifi.epizy.com/bekefux.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f3d4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF3D4 5500 bytes
SHA-256: d9a7fcbd811470311c2321f450c5b0cedf8fa6a7bb0a1a4944e325b9dbb3a227
font_01_sfnt_off0001065b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1065B 11116 bytes
SHA-256: c7e7204bb20ffa70b18bc26c2740d1e793724c392f530cc151a2111d2ca4ab81