Malicious PDF — malware analysis report

Static analysis result for SHA-256 84fd6d77667f7395…

MALICIOUS

PDF

78.4 KB Created: 2021-04-04 14:40:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 02bd91159133338bc17cac459776ca12 SHA-1: 292da70ff71a346a97fd268da75538d256a37b55 SHA-256: 84fd6d77667f7395ece01a1b80ad8465e6dddd17bcb979d5a91acbb8577de962
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which point to suspicious domains, indicating a link farm or phishing attempt. The ClamAV detection and ML classifier strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous external URIs suggest it's designed to redirect users to potentially harmful content, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=eurosys+2020+dblp
    • http://jibakerutev.mypressonline.com/define_direct_rule_system.pdf
    • http://bumululoru.mywebcommunity.org/bhagavan_nityananda.pdf
    • https://gejosubirimo.weebly.com/uploads/1/3/0/7/130776575/2867375.pdf
    • https://vafopizinenited.weebly.com/uploads/1/3/4/4/134480139/soratejugubes_gofudatibefug_rasiposajelamer.pdf
    • https://gunujudota.weebly.com/uploads/1/3/2/3/132303168/rugulazok.pdf
    • http://contact-git.top/how_to_use_forms_in_ms_wordjt60x.pdf
    • http://lnstagram-helping-centre.com/bins_to_donate_clothes_near_meywjor.pdf
    • https://silepokow.weebly.com/uploads/1/3/4/3/134366863/2ed7b63af.pdf
    • https://fipupoluvov.weebly.com/uploads/1/3/0/7/130775710/jorifixelewumagilik.pdf
    • http://movizopolu.medianewsonline.com/77419794540.pdf
    • http://kismykeitio.best/95846043751hdh39.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/3625d23b-65b7-4fe2-a04f-274af2704b38/harry_potter_5_illustrated.pdf
    • https://uploads.strikinglycdn.com/files/d19108c0-840f-4a11-bf52-3a79dcfaa9aa/reviews_the_gabriel_method_diet.pdf
    • http://vifidumefitur.atwebpages.com/4821259862.pdf
    • http://nofolimuri.myartsonline.com/brochure_background_design.pdf
    • http://sefamuw.rf.gd/roku_se_setup_instructions.pdf
    • http://xekofelix.rf.gd/gimavorovivo.pdf
    • https://f79c4d19-9b07-4ca9-ba82-4f938217db57.filesusr.com/ugd/c0d3e8_fa7b89baafc24f918b14d2ca27344098.pdf?index=true
    • https://bef89f6e-6323-4b84-ad9d-a44490bfcc4f.filesusr.com/ugd/96768c_987330f5a8e74fa19a6de343872870c5.pdf?index=true
    • https://uploads.strikinglycdn.com/files/8f853853-7985-4011-be17-0c885415408f/how_to_put_car_seat_cover_on_safety_1st.pdf
    • https://11ca5eb4-0abe-4d5d-8073-3f36f6088e80.filesusr.com/ugd/8b62d8_a9c5a2b4dac14a0dacf8d5e902fe0993.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f314.bin
ae376531259b263a9019573a2c1c9351be60e5f38da580498f337adab6e92591
pdf-font-stream PDF embedded font (sfnt) at offset 0xF314 5216 bytes
font_01_sfnt_off000104de.bin
0f30560ca3e1e18da57e62d8f7677513659e39d7fdc982a0a8727a9fde61c4de
pdf-font-stream PDF embedded font (sfnt) at offset 0x104DE 11320 bytes