Malicious PDF — malware analysis report

Static analysis result for SHA-256 86ea880b2a959daa…

MALICIOUS

PDF

91.7 KB Created: 2021-03-20 08:00:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-02
MD5: 26c1ed070918287b023c6c50e147915b SHA-1: 22de6d4ffcaed2a06e56a2bfe3c354f904c6bcf3 SHA-256: 86ea880b2a959daa9dc9ae15e6b499dac559e065d5a799cdc7c54126e2b51914
244 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by multiple heuristics and an ML classifier, and detected by ClamAV as Pdf.Phishing.Trojan. It contains a large number of embedded links, many pointing to disposable hosting, and at least one known malicious redirector URL. The document body, though heavily obfuscated, appears to be a lure related to 'John Henrik Clarke books pdf'. The primary attack pattern involves directing users to malicious websites, likely for phishing or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=john+henrik+clarke+books+pdf In PDF document text
    • https://pidoruna.weebly.com/uploads/1/3/5/9/135966994/9966215.pdfIn PDF document text
    • https://tifixexeruwa.weebly.com/uploads/1/3/2/6/132682204/nivaxajo_vowuk_gukiga_medagupanologer.pdfIn PDF document text
    • https://nukofagola.weebly.com/uploads/1/3/4/8/134883999/lutolexejosap-ribot-zolajemelamivuz.pdfIn PDF document text
    • https://xatuzagu.weebly.com/uploads/1/3/0/7/130738971/lobibikewobone_kiniwoponovikom_mugowonedededet_towexoru.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/0c159fa9-4c57-40da-8076-59134c20186a/nilulevawezejalubibas.pdfIn PDF document text
    • https://6ddb26ad-aa8e-4a3e-a925-5cef6fc035e1.filesusr.com/ugd/d3d820_71e23d575829466fb35f340dd46eb513.pdf?index=trueIn PDF document text
    • https://d4f1f58f-bd44-402a-a4b0-a3aa01e36dbf.filesusr.com/ugd/dffefa_d752367f9e89476c92846911e3767c2b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/3252bbcc-421a-443c-888e-056460113ed8/starbucks_cold_cup_uk_price.pdfIn PDF document text
    • https://s3.amazonaws.com/ronatiduzoxij/expository_sermon_outline_template.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/315d1272-363b-48cd-b65f-2ec62f558b0a/buxojajuzuterudovanowo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/650bc141-3704-4d59-af1d-07856df23c72/diccionario_biblico_cristiano_reina_valera_1960.pdfIn PDF document text
    • https://s3.amazonaws.com/xakajoziwibi/nixil.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9c5c96af-c3e9-4568-8da5-d79dd105f9d2/177_mental_toughness_secrets_of_the_world_class.pdfIn PDF document text
    • https://s3.amazonaws.com/megelugik/causative_have_transformations.pdfIn PDF document text
    • https://4ef57e19-9a2e-4e6f-a444-f6b59f982a39.filesusr.com/ugd/4c1554_e93fe38d14ec4334b5febe141554fc44.pdf?index=trueIn PDF document text
    • https://e6e31949-ba74-43ae-8e0c-2243355e89fd.filesusr.com/ugd/69e259_8e33f337751642ca95c13e0fed8aaf1f.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/6ba73696-4477-469a-a068-5f1406ea8d63/39540332871.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/82d83b35-0242-4674-9ad7-3415585c298c/67125879810.pdfIn PDF document text
    • https://77ac2d45-d533-4b4b-a85c-01e81860bff9.filesusr.com/ugd/7f1ad7_f40bd7f63a854ff6b527a2fd46dc2637.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/0fea78d9-5e09-43f8-b331-6594f0ed5f8f/pavobinebavezewomisav.pdfIn PDF document text
    • https://a3c35cc3-4a3f-4d41-ab51-8b3e4b114d30.filesusr.com/ugd/2b25b5_62aa5f1e005c408dbf1bd98ff22b2bb0.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/e71fc66f-616c-4f18-bcef-8fe962ea486a/us_army_red_cross_message_format.pdfIn PDF document text
    • https://s3.amazonaws.com/jejulurowev/what_to_do_when_your_wireless_mac_keyboard_stops_working.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012974.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12974 5436 bytes
SHA-256: 6f57a5ec0357ea0a05b21b50da7f43ec797a366f95da1a83f7743fd413189db6
font_01_sfnt_off00013be3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13BE3 10916 bytes
SHA-256: b21078ff88ae6222cc2dbba282b0f68e4b5064426847e4abcc318441d8799df9