Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b9e6877091504d2…

MALICIOUS

PDF

81.1 KB Created: 2021-03-07 22:07:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-26
MD5: 247d9271d60ccba36e8d5df227478068 SHA-1: 82cf2befe7a304c8af4772adf10a62130cb32745 SHA-256: 8b9e6877091504d23d11cb5ace3216aa5ffeedaee1ae34e570f4a2c1af7c3c1e
134 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple external URIs, with a high-confidence ML classifier and ClamAV detection indicating malicious intent. The document body, though heavily obfuscated, suggests a lure related to 'review answers', and the presence of PDF_SEO_DISPOSABLE_LINK_FARM heuristic points to a link farm strategy. The primary malicious URLs identified are likely used to host or redirect to a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/wix?keyword=chapter+7+nucleic+acids+and+protein+synthesis+review+answers PDF link annotation
    • http://gosepakaf.getenjoyment.net/prohibido_enamorarse_de_adam_walker_3.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4428341/normal_5fcf02dfe23a0.pdfIn PDF document text
    • https://cdn.sqhk.co/jolodovi/ghjvtPa/84118584368.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4409123/normal_5ffc67a1a7af1.pdfIn PDF document text
    • https://cdn.sqhk.co/vumivatuvi/ifgihcz/dovujujorovowikututenaz.pdfIn PDF document text
    • https://cdn.sqhk.co/naxibibu/fqEhhgh/16346175379.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4421461/normal_5ff1f68f04982.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374374/normal_6038fd79b0cc4.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4487903/normal_5fc85eb80b681.pdfIn PDF document text
    • http://dipenoguzel.sportsontheweb.net/what_are_the_main_problems_in_society.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/f0fb4120-4915-4c00-9672-132fbcc5d3d9/possible_jobs_for_information_technology.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9f4a404f-d8fd-4f82-b671-5a32c3398b40/28620179707.pdfIn PDF document text
    • http://kofaxafogi.myartsonline.com/nebafewezufizepesawoma.pdfIn PDF document text
    • https://67d298e0-85f4-4ad4-bf36-e1ac857e42fc.filesusr.com/ugd/b6bf5b_67ef0ec813014db7b51987b4e0f67595.pdf?index=trueIn PDF document text
    • https://7e005a1c-fb68-43c1-af83-b854b6a2d282.filesusr.com/ugd/dcfb95_34b5ec9123684d13b4857fa7938603ce.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/d126485d-7bca-4bb5-9e3e-02e1144a2c37/98912490679.pdfIn PDF document text
    • https://bd15da75-ee01-4ad3-8b22-4778d9929f37.filesusr.com/ugd/1abc29_b3a45b9017c2487493c646bed8427e1e.pdf?index=trueIn PDF document text
    • https://769966b8-4adc-437e-bba8-f198cf6e171b.filesusr.com/ugd/41a0b6_5bbf2653b8e54a57a6feebb2b2603b94.pdf?index=trueIn PDF document text
    • https://80c8fd16-4cf8-4f9f-b52b-d6c956df8f3b.filesusr.com/ugd/1a94e8_5be57fd0b9d44224b08db0b2d4c1f36c.pdf?index=trueIn PDF document text
    • https://d6504552-49b0-4b7d-b1ff-94f9e1082b83.filesusr.com/ugd/1f0558_e77f209c2cdd44ecad848b420c37674c.pdf?index=trueIn PDF document text
    • http://nununad.myartsonline.com/17710440575.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/615b1626-f6a6-481e-84ee-8309f6c47240/83704412649.pdfIn PDF document text
    • https://f1cb2ec4-a82d-4768-8a06-5236a2db220e.filesusr.com/ugd/a2e20a_f429d048200b4673b264ff859f21ac74.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010011.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10011 5400 bytes
SHA-256: 5ba74cab27b264e2c58b976e9ae9c3f64c19326a6363baf3ffc122b57c7f2477
font_01_sfnt_off00011283.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11283 10556 bytes
SHA-256: 5c9fcf604467c236ee6c74e29de9b38542ab5b78ae0dc09eef76db5318773fff