Malicious PDF — malware analysis report

Static analysis result for SHA-256 7fa8010b063a9369…

MALICIOUS

PDF

79.9 KB Created: 2021-04-12 06:24:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 6e8a57dd0514827f440a20089a04e406 SHA-1: 60c4cd5416949854c64c7718cd785350b83521e4 SHA-256: 7fa8010b063a93691a94bc665143b6ed0ae9013e5691dcece0e4b6b6f80909c5
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, many of which point to disposable hosting and are used in a link farm, a common tactic for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. The document body, though heavily obfuscated, contains a technical support-related query, suggesting a lure to trick users into clicking the malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/strik?utm_term=how+do+i+fix+lenovo+preparing+automatic+repair PDF link annotation
    • https://cdn.sqhk.co/mixaluwekitu/igijiaO/first_home_buyers_program_in_ohio.pdfIn PDF document text
    • https://cdn.sqhk.co/lomabufu/qmIcKge/dilunu.pdfIn PDF document text
    • https://cdn.sqhk.co/purilusevike/Hgcicbj/the_last_blade_2_rollback.pdfIn PDF document text
    • http://vonexalux.sportsontheweb.net/attestation_de_non_affiliation_cnas_algrie.pdfIn PDF document text
    • http://gokawojop.scienceontheweb.net/algebra_1_textbook_online_mcdougal_littell.pdfIn PDF document text
    • https://cdn.sqhk.co/rabataxuvax/iblJjdq/sync_icloud_photos_to_mac_high_sierra.pdfIn PDF document text
    • http://rujurag.22web.org/53494349906.pdfIn PDF document text
    • http://setirexude.22web.org/list_of_emotions_in_english.pdfIn PDF document text
    • http://monubagujizud.mywebcommunity.org/functionalism_philosophy.pdfIn PDF document text
    • http://tuvimokasodo.22web.org/vakopabalofozejopux.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/dd390e08-9c68-4af4-8b09-a3b1b86bea7f/muwus.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d98460c9-9a09-4ff6-ade4-4d742cf1d6dc/examples_of_symbolism_in_sinners_in_the_hands_of_an_angry_god.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/85947fb1-bb5f-411a-a57e-44a4b31eb09e/fuziradedizolow.pdfIn PDF document text
    • http://nowageg.onlinewebshop.net/nivamevubakupudofuxeli.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/60d47e5e-1843-4879-ade8-155d0884b4ca/pefopujagukaxufazuxeton.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5117b526-f155-40a4-9825-698cfcd0f8ef/12160296015.pdfIn PDF document text
    • http://kewivifonawati.epizy.com/chopin_ballade_n_1.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/41d5e400-f9fb-44b8-a3f5-c93e5f7432cd/quadratic_equation_problems_with_solution.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f2bf328d-bdea-44a8-90e7-f16c0c2d7768/rarofumuxoz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/70aec4a1-f5eb-4ead-881d-094fbcbcfd5a/is_proform_better_than_nordictrack.pdfIn PDF document text
    • http://tufuripisaren.epizy.com/bulova_marine_star_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/be65e7db-e22f-409d-885b-614a3f715c8c/14907436820.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/58011cef-6a1c-4517-83c3-c24070396e84/7139888378.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea7b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEA7B 3312 bytes
SHA-256: cb5c8c6405a97e289a1d37fd8f3fa0fb9a9e5cd02c3f475be668e5c7f8c23a8c
font_01_sfnt_off0000f65c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF65C 5480 bytes
SHA-256: 8660558f4284d0da5305144021082f326ca4a75357eaf3fc31f1b27b710264e1
font_02_sfnt_off0001090a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1090A 11500 bytes
SHA-256: 5860d27e0a07d30997082311813858fdbd2f09f2f24b919f9bef9cd87fdb64a8