Malicious PDF — malware analysis report

Static analysis result for SHA-256 7aa87f73f0daa30d…

MALICIOUS

PDF

80.0 KB Created: 2021-05-27 19:36:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-20
MD5: ac7c5031612a13665fc65e704029ec78 SHA-1: 2197c0b554df5a1bc6704f04d1312c63f9b0d1bd SHA-256: 7aa87f73f0daa30d575ccfa6bc80fcd2d224cb8c029bd00d796d4862f8bad82d
204 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many pointing to SEO-optimized content, a common tactic for phishing or malware distribution. The presence of a 'download button' lure and a critical ClamAV detection for 'Pdf.Phishing.Trojan' strongly suggests a malicious intent. The primary malicious URL identified is fokemale.ru, which is likely used to redirect users to a harmful payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fokemale.ru/strik?utm_term=resumen+del+capitulo+11+de+cien+a%25C3%25B1os+de+soledad PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4486778/normal_5fd1f6fb04c0b.pdfIn PDF document text
    • https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/6050092.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4419650/normal_5fc8159bd25ba.pdfIn PDF document text
    • https://menekagamop.weebly.com/uploads/1/3/4/0/134097565/2c78f629ad.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/ddbd9f6c-16e5-4e6f-90ab-8ab6ef68555f/how_to_reset_sonicwall_tz_205.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/60a03b54-f16b-47c5-b7d1-8020525724a1/orpheus_and_eurydice_sheet_music.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4ead12dd-5969-4b23-ad62-b9f59a0dbb2f/69693105489.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2c2d378d-049f-49de-8fc8-9d9a89696648/how_to_do_flash_chromatography.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f991d61b-2ed8-48ec-9a25-789d7e0b452b/unit_operations_of_chemical_engineering_6th_edition.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cdccef85-2591-48f3-b0e4-4f3bceafc2f1/big_rock_blue_marlin_tournament_live_stream.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e2dc6a9d-af0a-432a-ac55-47b5f1c9ae7d/sonic_blast_menu_2020.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/463e4ea6-02f8-4ab9-bbbc-c363153011ef/xitonitebi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/98af9177-fd9e-47ad-b551-dbd9ab856b95/local_area_network_lan_settings_windows_10.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/24aab43a-537a-4f8e-b945-f0d22ab49d64/central_pneumatic_air_compressor_6_gallon_review.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/75e665fe-035e-4d0c-98fe-1b310be8e0df/vikopagoju.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ad315a2c-faef-4457-94d6-82354d967d8f/ap_psychology_midterm_review_sheet.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0578d8e7-aedf-407c-b16f-4414f512910c/dark_souls_3_ringed_city_ending_reddit.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/24c680c5-c605-4ed1-8560-709a675279bc/mass_of_joy_and_peace_sheet_music.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b41c1f18-3875-4d83-a7da-cd7e45186658/93003474545.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9d9babfc-e211-4146-836b-e7a1c533ca61/ejercicios_resueltos_de_energia_potencial_y_cinetica.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2ec2f8aa-2e36-45a2-aebb-837cb9f12793/rain_dial_plus_user_manual.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f879.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF879 5392 bytes
SHA-256: 36db77caee3292ffa9e62e24c21ab4baffa9dc51bf26e31ea41f817932565716
font_01_sfnt_off00010a8a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A8A 10908 bytes
SHA-256: 4eb1d72ba5202e6f470b74fa1dbc954530f9a954d347bbdc49c8b37a3fba62c0