Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b2d01c518bee701…

MALICIOUS

PDF

85.0 KB Created: 2021-05-08 07:50:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 447450f1f9b16ebeb728a9e0065b7433 SHA-1: f7d9cb930f786d3b8c267f5a00b9a6fe3b56043c SHA-256: 8b2d01c518bee70138f311de81f448be40ba16f876d34c046795e69a4cf1e6ad
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many pointing to disposable hosting, and is flagged as a link farm. The document body, though heavily obfuscated, suggests a lure related to a 'Proform 415 lt treadmill manual'. The presence of external URIs and the ML classifier's high confidence score indicate a malicious intent, likely to redirect users to potentially harmful sites or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=proform+415+lt+treadmill+manual PDF link annotation
    • http://liketime.online/xinozemosalisagurutefojaza30pe.pdfIn PDF document text
    • http://blog-millionaire.buzz/traveller_magazinexci61.pdfIn PDF document text
    • http://astropsychology.website/modo_de_produccion_asiatico_clases_socialesrcu3b.pdfIn PDF document text
    • http://sekijad.iblogger.org/69171345884.pdfIn PDF document text
    • http://ketizivo.22web.org/diwapexupag.pdfIn PDF document text
    • http://lnstagramaccounts.com/vuxesewabavifuloposozirhuf9.pdfIn PDF document text
    • http://hookup756.fun/pasoreromoxupuwawovakadeoqnvl.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/12d6b6f1-d3e8-450f-8488-d99fa824acf8/vivepovujikubawafatakozi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bafb164d-c1e6-4e75-b109-4a0bc4cfa906/gozeraxupobedezisun.pdfIn PDF document text
    • https://0491f86b-060d-4f4a-be23-b0d01488777f.filesusr.com/ugd/faa7ef_13d40e013c2041bfae416fd118fc4f80.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/5ea82ba0-d53e-4498-9873-a1aff77cbfdd/51059995595.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b57e005a-b583-4078-942b-cb08af512803/korizadojowutopoturazijax.pdfIn PDF document text
    • https://s3.amazonaws.com/ladojenefe/mathematics_for_economists_answer_key.pdfIn PDF document text
    • https://e905e09d-7ddd-4aab-833c-73500e817873.filesusr.com/ugd/f4c08b_71574fc0eeda4fe3a6835bb4df1949c4.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/rerinago/hazardous_waste_guidelines_ontario.pdfIn PDF document text
    • https://ea74ff18-003d-4094-8454-8d7e15e33abb.filesusr.com/ugd/50de67_dfa03b043a6445c080a1fe2caf4844ff.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/82bd48c1-61c7-449f-8d7e-45eaafc0221e/88308936986.pdfIn PDF document text
    • https://cb70cc59-2297-49c3-b7e2-2ac7e26e28d4.filesusr.com/ugd/4479ed_79c23d21f35e41168fef76c3aebd74c5.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/200b0609-b94a-4db1-a144-2bc1347aa0c8/5531948678.pdfIn PDF document text
    • https://s3.amazonaws.com/jawusawar/samsung_india_csr_report.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010067.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10067 5140 bytes
SHA-256: 533aa269a008d6c7df29dbf4db0ffe8e0815933f10745b63adcd09a7e75020ef
font_01_sfnt_off000111d3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x111D3 2412 bytes
SHA-256: 5a5d34b7b6c642d7a756e2097f4620240f574e12f5849df4a5325dd4c813a032
font_02_sfnt_off00011b58.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11B58 12692 bytes
SHA-256: f231ec049e902c667d55fb6f4927117b80e5fd35d1f7995020f54240ddf559e0