Malicious PDF — malware analysis report

Static analysis result for SHA-256 8474563fd16aa1a6…

MALICIOUS

PDF

78.6 KB Created: 2021-03-19 23:19:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-20
MD5: 0bd3fdc03a1b1b9d6e4cec1274d0a0ae SHA-1: 244d14afb5ca8a0481ab5e6c6d398769879fb545 SHA-256: 8474563fd16aa1a67c1b0b502ad36c26aaa9f6be06fbfa2e1594820689c8f7f9
206 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many of which are part of a link farm, suggesting a malicious intent to redirect users. One prominent URL, 'https://golowaki.ru/strik?utm_term=ethical+hacking+course+in+sri+lanka', appears to be a lure. The presence of a 'PDF_SEO_LINK_FARM' heuristic and ClamAV detection further supports a malicious classification. While no scripts were explicitly extracted, the structure and heuristics point towards a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/strik?utm_term=ethical+hacking+course+in+sri+lanka PDF link annotation
    • https://jematujevuzonip.weebly.com/uploads/1/3/4/2/134235480/jukakutarekifuxubuw.pdfIn PDF document text
    • https://vekewofamir.weebly.com/uploads/1/3/4/1/134131384/xixufu-vifipoxikavi-tanofozem.pdfIn PDF document text
    • http://avit0.cc/progressive_relaxation_guided_meditationn6cuy.pdfIn PDF document text
    • https://jidevamomibowi.weebly.com/uploads/1/3/1/4/131437101/bavitok-jokejovakurisol-leposazipuxe-pigak.pdfIn PDF document text
    • http://dubiniba.iblogger.org/how_to_set_sales_tax_on_casio_hr-100tm.pdfIn PDF document text
    • http://optarfes.com/personajes_del_libro_el_coronel_no_tiene_quien_le_escriba51unu.pdfIn PDF document text
    • http://helen-art.ru/que_es_la_introduccin_en_un_trabajo_escrito_ejemplotlsrg.pdfIn PDF document text
    • http://italdom.fun/raging_bull_big_and_tall_size_guidetgjmk.pdfIn PDF document text
    • https://vovavurag.weebly.com/uploads/1/3/0/7/130739927/277d6bef0cd5.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jalasilunaz/barnes_and_noble_nook_book.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d4f17516-fd84-4dfe-85d9-f52f4c1b88d8/fepolozepi.pdfIn PDF document text
    • https://s3.amazonaws.com/befafuni/how_to_apply_a_vinyl_decal_to_your_car_window.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/89ab2f4f-e9a6-4784-9285-51001a6deda2/konosuba_light_novel_volume_12_epub.pdfIn PDF document text
    • http://zoxipugezamubuf.rf.gd/add_reminder_video_cast_android.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1be8c857-071c-451c-bdde-e72591200d6d/is_how_the_grinch_stole_christmas_on_netflix.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bbcf91b6-0798-4a8b-b04f-c2244866969e/41125817159.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6d997238-3a44-48a1-a4ec-b6033f5e8bde/15297992803.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7acaab2d-6bb8-4ab2-b8b5-074618479f9a/do_androids_dream_of_electric_sheep_chapter_2_analysis.pdfIn PDF document text
    • http://muwalolerede.epizy.com/army_cadet_uniform_ironing.pdfIn PDF document text
    • https://s3.amazonaws.com/penale/mugeputowez.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ef15bb78-e163-4fd5-9d77-963e7614068d/what_is_non_realism_in_theatre.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f43d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF43D 5084 bytes
SHA-256: 3682f630ed82773761df1e6029ba68584456043cc23655a60c87ca6452f0c6be
font_01_sfnt_off00010585.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10585 11112 bytes
SHA-256: 1df73acf5ecda8468378a0355b3581197340f710892f31b336cde5719d00dba4