Malicious PDF — malware analysis report

Static analysis result for SHA-256 8544714787db32f4…

MALICIOUS

PDF

81.7 KB Created: 2021-04-02 06:13:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 14c89ecd8cd152302efc537f29acbe4a SHA-1: 75a814648c30a2f55ac47adbce0fbf7bf9188135 SHA-256: 8544714787db32f41a98f4d7386c96077824b74a0912a669a4f90a72da1ec94f
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many pointing to disposable hosting or unknown domains, indicative of a link farm. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or distributing further malware. While no scripts were explicitly extracted, the PDF structure and numerous external links suggest it's designed to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=pioneer+ddj+sx2+price+philippines
    • https://nujazovarurep.weebly.com/uploads/1/3/1/8/131856890/4ebcced4235768.pdf
    • https://fuwidomanajano.weebly.com/uploads/1/3/0/8/130874101/gevavokovipibaji.pdf
    • http://zarabatyivat.ru/2929958706kuguq.pdf
    • http://tdsevsvet.ru/fasidurebopinexipakiveviniiup.pdf
    • http://devgm.design/how_to_clean_a_browning_2000_shotgun2mmzx.pdf
    • http://wersita.space/best_price_bose_wave_music_system_ivqlvwz.pdf
    • https://wexemexaxixu.weebly.com/uploads/1/3/4/7/134709907/6663623.pdf
    • http://uscarins.info/how_to_pronounce_arabic_words_in_englishod3zx.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c738f208-49b2-47f9-97fb-628f9522f948/17136750590.pdf
    • https://f55c6975-0091-4942-a106-dc80285e5f9d.filesusr.com/ugd/8a4248_6d0ffaea3dbf4d508a797c392fef8d9a.pdf?index=true
    • https://s3.amazonaws.com/zasepo/air_conditioning_system_nptel.pdf
    • https://97a45c9e-1ab5-462a-bfe2-fded34b9a8b9.filesusr.com/ugd/b50c55_df285b07a7804f1a9d62a9c7765f596a.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a1735dbb-b954-4f52-b470-28e560788180/how_to_do_an_average_of_an_average.pdf
    • https://b19b3b79-9ae2-4e99-9b16-ef32671d60f4.filesusr.com/ugd/0bc867_d1aa427a86714a709f465efd1bf78daa.pdf?index=true
    • https://uploads.strikinglycdn.com/files/0d1efae8-7375-4c78-a0fd-a5fef62cac0a/gramatica_de_uso_del_espanol_b1_-_b2_teoria_y_practica.pdf
    • https://a5a8f6e1-24ae-425c-880d-6f4079e3c376.filesusr.com/ugd/035627_3348b921af7e43d785de54d9c1fb4341.pdf?index=true
    • https://s3.amazonaws.com/dadupawo/vedalez.pdf
    • https://s3.amazonaws.com/resixexi/balagudazedidix.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000de55.bin
65da4e37e64f9b22eb917ca787c745809f814d4a024d439e041960d4c4bcafa9
pdf-font-stream PDF embedded font (sfnt) at offset 0xDE55 2984 bytes
font_01_sfnt_off0000e8f9.bin
d30f738515a2ed5e960825ae084923d47ca2d2db4564b1af99d7b18f454ae93d
pdf-font-stream PDF embedded font (sfnt) at offset 0xE8F9 5228 bytes
font_02_sfnt_off0000facd.bin
c1200af994e16b4a7ac4c8b339815180cef04315454e485c9a073a0d5004f3d7
pdf-font-stream PDF embedded font (sfnt) at offset 0xFACD 11420 bytes
font_03_sfnt_off00012196.bin
9605cbd26af1344ff699f24a1baa1cc0d6f612157c64674cace4ad90e2237248
pdf-font-stream PDF embedded font (sfnt) at offset 0x12196 16936 bytes