Malicious PDF — malware analysis report

Static analysis result for SHA-256 89f165ebf186e806…

MALICIOUS

PDF

93.1 KB Created: 2021-05-30 00:11:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: eb069f4e0b00e65fd0ff980ae979494a SHA-1: 163b440804c9e17e7d270af1c5ed1c2e2004d828 SHA-256: 89f165ebf186e8060db15fdbdf26aa0d585b80216666bd94076b71d4a557a628
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file is identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a large number of external links, many pointing to disposable hosting, suggesting a link farm designed to redirect users to malicious sites. The document body, though heavily obfuscated, appears to be a lure related to 'Estilos de afrontamiento en adolescentes pdf'. No scripts were extracted, but the presence of numerous external URLs and the overall structure strongly suggest a phishing or content-scraping attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=estilos+de+afrontamiento+en+adolescentes+pdf PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4387232/normal_5fee6e7a28bb4.pdfIn PDF document text
    • https://lafapimiwegu.weebly.com/uploads/1/3/4/0/134041150/balujuwuke.pdfIn PDF document text
    • https://kivobuduzuv.weebly.com/uploads/1/3/0/7/130739084/xejaruner-sufimaz-bajofipoda-zinigogo.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4408343/normal_600247a5853a6.pdfIn PDF document text
    • https://foxogitasi.weebly.com/uploads/1/3/2/7/132740511/67ac08a9534.pdfIn PDF document text
    • https://xopomosafeg.weebly.com/uploads/1/3/4/7/134732974/zojama_pemamobeza.pdfIn PDF document text
    • https://wabuxopimigom.weebly.com/uploads/1/3/4/0/134042903/7812233.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4496582/normal_602783504459b.pdfIn PDF document text
    • https://vowebaxuzifov.weebly.com/uploads/1/3/0/7/130738870/ponivomatexago-mowaduzajirilup.pdfIn PDF document text
    • https://valiwuvubeke.weebly.com/uploads/1/3/4/6/134694219/a389cf3.pdfIn PDF document text
    • https://fevuvewuvadudu.weebly.com/uploads/1/3/4/6/134650824/wukud-fakat-zumodiginofuk.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/c0124ac4-e017-4b77-a5a6-ddf3cb7e394f/being_happy_tal_ben_shahar_free.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/abf3d8bd-8f1b-4b32-b6b2-d6c363a341b6/can_you_use_rental_income_for_fha_loan.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/66d557c6-39b8-457d-9962-bf3d9e1e0774/how_to_reset_ink_epson_l3110.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c62eeb8b-dc0b-4c13-8082-3d162b2eb8a6/jowizagi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7109761d-7c8f-4fec-901d-f3a962e2dc43/bombastic_words_for_essay.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a11f3fb2-1061-4bb3-b133-9f3dda2edf1f/illustrator_minimum_system_requirements.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cff77f3f-b5d3-488f-a47d-4ca7d73924a2/The_final_barber_shop_Amsterdam_Avenue_New_York_NY.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012d1b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12D1B 5256 bytes
SHA-256: b9002fd899dcd7ee866bfc2f3d74df889442342fe89e836b6e3001af2914ee48
font_01_sfnt_off00013ef0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13EF0 12296 bytes
SHA-256: 42183e63bbf0b60d4935dbd5f0ba61d78006173b2bc9565bda5ca0b045c7d425