Malicious PDF — malware analysis report

Static analysis result for SHA-256 87c0294508ee57a9…

MALICIOUS

PDF

78.2 KB Created: 2021-04-23 19:04:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d572439d7135859bc41cafab604ff57d SHA-1: b07a636ce220c5f78a1401aa68dec36afb722a94 SHA-256: 87c0294508ee57a9b1ee8ee6291d5d8f4b0a0f050f8976b23e76350a9bf7f587
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, indicating a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly support its malicious nature. Although no scripts were extracted, the document's structure and embedded URLs suggest it's designed to trick users into visiting malicious sites, likely for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=learning+sight+word+activities+for+kindergarten
    • https://cdn.sqhk.co/gitaligido/ijCwJgi/chicken_invaders_5_trainer.pdf
    • http://zeludupixejufi.medianewsonline.com/xekasusojawepa.pdf
    • https://cdn.sqhk.co/zavipudajose/ahhzWhe/mad_skills_bmx_2_pc.pdf
    • https://cdn.sqhk.co/vodadavubex/hgi2hba/.pdf
    • http://zathkatow.xyz/62342130734a4sjf.pdf
    • https://cdn.sqhk.co/rajunakeb/a9ieOya/jimowatoginasaroxonigo.pdf
    • https://cdn.sqhk.co/godezixibufo/SiWTlgh/parachute_health_sign_up.pdf
    • https://cdn.sqhk.co/puwidebudojo/hgccEhj/mci_airport_hotels.pdf
    • https://cdn.sqhk.co/pujixefan/3ijLzzc/20591410186.pdf
    • https://cdn.sqhk.co/xolofiwano/jNhBGjh/tower_defense_zone_2_mod_apk_android_1.pdf
    • http://pakizimavom.scienceontheweb.net/stoner_john_williams_english.pdf
    • http://sberbank.services/accidents_reported_today_los_angelessfz76.pdf
    • http://sedouche.xyz/14242573650cveo7.pdf
    • http://fijexojor.getenjoyment.net/35437621974.pdf
    • https://cdn.sqhk.co/jomonufo/hahbZOb/lynx_lake_fishing_tips.pdf
    • https://cdn.sqhk.co/dabigewom/LEngdOw/qr_code_scanner_online_from_image.pdf
    • http://zolepop.mypressonline.com/carcinoma_papilar_de_tiroides_tratamiento.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/9a692425-fe55-4c08-9014-18767cd717b5/how_does_the_author_influence_the_reader.pdf
    • http://butorinowu.myartsonline.com/vizatekajewaz.pdf
    • http://butorinowu.myartsonline.com/18454911768.pdf
    • https://uploads.strikinglycdn.com/files/43af7709-e3e7-4967-98ef-2707cb0270f3/what_are_the_elements_of_estoppel.pdf
    • https://uploads.strikinglycdn.com/files/8def5dc2-38cd-49ea-86f0-f1b7d70c84ee/onyx_ezr_with_vehicle_kit_installation.pdf
    • http://lugimeviguv.myartsonline.com/69328947611.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f03d.bin
c3107112b9aa36a394a3c05a9dec763022f7b0a276ad7a058edd8afe043cdb1b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF03D 5408 bytes
font_01_sfnt_off000102bc.bin
96a3006d6fdec68cf60bb3b8d440f11cc4553e77e6b1ff3c3383d60204f98409
pdf-font-stream PDF embedded font (sfnt) at offset 0x102BC 12064 bytes