Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a01dc91fcc0f82a…

MALICIOUS

PDF

75.9 KB Created: 2021-06-12 00:35:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: c4366fd6bce751d95cf795f586d5a769 SHA-1: 5803012e01fe3ad5e605e85a68d53f95f7391e78 SHA-256: 8a01dc91fcc0f82a2f29005e948bdb76b7f550042041d999e9b6150bb73802d6
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file is identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan distribution attempt. It contains a mass of external links, many hosted on disposable domains, suggesting a link farm designed to redirect users to potentially malicious content. The document body is heavily obfuscated, but the presence of external URIs and the PDF_SEO_LINK_FARM heuristic strongly suggest the primary purpose is to drive traffic to these external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://catamma.ru/pbw?utm_term=halliday%2527s+seven+functions+of+language PDF link annotation
    • https://static.s123-cdn-static-d.com/uploads/4464323/normal_60b33d5b661cc.pdfIn PDF document text
    • https://gidelusibi.weebly.com/uploads/1/3/4/0/134040719/logekikesasa_kawevuxif.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4459630/normal_602aca711eb16.pdfIn PDF document text
    • https://dabawide.weebly.com/uploads/1/3/7/5/137511183/2469eaa3994fc.pdfIn PDF document text
    • https://muwirejevom.weebly.com/uploads/1/3/1/8/131857435/eb175b1e966d5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4421462/normal_6066e513ea087.pdfIn PDF document text
    • https://kanodofeju.weebly.com/uploads/1/3/5/3/135325650/borawoboko-wupagodorukixiv-newuduke-bemudogabebadod.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4417534/normal_5fcc5f840bcc5.pdfIn PDF document text
    • https://moremutinujiti.weebly.com/uploads/1/3/4/8/134865562/jijewe.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4476767/normal_601ae3ea7e4c3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4386836/normal_6060af0df3868.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4418367/normal_5fd1d2a29b06f.pdfIn PDF document text
    • https://fesimubigezati.weebly.com/uploads/1/3/4/5/134515628/2533996.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://gupiguna.pbworks.com/f/tisafoval.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/563e5d74-8497-4e24-bdf9-7c9cc590610b/gowugabekubuvutadawi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/27c622dd-64c3-4aa7-820e-c4f536543908/ktm_300_exc_user_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d89edb63-7d5b-4175-ad33-cc0964a341f1/62665095753.pdfIn PDF document text
    • http://xulajirose.pbworks.com/f/shinmai_maou_no_testament_season.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/87dd6e40-eadb-47f8-a785-5c7fc7c0ee10/why_does_my_nest_thermostat_keep_going_offline.pdfIn PDF document text
    • http://sozakuvepar.pbworks.com/f/broski.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c67bbb1c-c3b4-4a64-9529-2d8c6e33a5d3/tipos_de_sistemas_operativos_servidor.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ddd8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDDD8 5132 bytes
SHA-256: 25a9bf9e4c7f589d3312ee59af85a387c78fc5844174ec99242023404f8adbbe
font_01_sfnt_off0000ef75.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF75 10732 bytes
SHA-256: d1dbb94d7785878e7206ee1b3b78fcaee2cd0b02ca3c1be99a8204b6c759d898
font_02_sfnt_off000113e6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x113E6 4324 bytes
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3