Malicious PDF — malware analysis report

Static analysis result for SHA-256 8d8c138375c7fbf9…

MALICIOUS

PDF

78.9 KB Created: 2021-06-01 17:43:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 45ee0ac3bc7a329d62b5922cfcb1a92d SHA-1: 6714591f0aca77ee345a4d1a03a0433bd8862e06 SHA-256: 8d8c138375c7fbf9540798d8f9954b9ba6851dd5df26c3b247dcd5d481a291ee
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous embedded URLs, many of which point to disposable hosting and are part of a link farm, indicating a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or delivering a secondary payload. The document body's deceptive title about chargeback rebuttals is a common lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9476

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://oniceh.ru/pbw?utm_term=how+do+you+write+a+chargeback+rebuttal+letter
    • https://doxigexuwalo.weebly.com/uploads/1/3/4/7/134708718/sawunek_tajamug_tijujovot.pdf
    • https://static.s123-cdn-static.com/uploads/4427103/normal_5fee4729c32a6.pdf
    • https://static.s123-cdn-static.com/uploads/4494430/normal_5fcddebb174f8.pdf
    • https://jomigotub.weebly.com/uploads/1/3/4/7/134748998/390407.pdf
    • https://cdn-cms.f-static.net/uploads/4459170/normal_601eea053ad7c.pdf
    • https://cdn-cms.f-static.net/uploads/4483851/normal_600ccd07a991d.pdf
    • https://static.s123-cdn-static.com/uploads/4389801/normal_60006b88278ca.pdf
    • https://melejorun.weebly.com/uploads/1/3/0/7/130775242/newebax.pdf
    • https://ronuviwa.weebly.com/uploads/1/3/4/5/134587060/f0ed3d4.pdf
    • https://gapuromediwav.weebly.com/uploads/1/3/0/8/130814643/4339073.pdf
    • https://cdn-cms.f-static.net/uploads/4450042/normal_606c4aafacebd.pdf
    • https://cdn-cms.f-static.net/uploads/4453734/normal_6067de0bb03e9.pdf
    • https://cdn-cms.f-static.net/uploads/4415073/normal_6016fd530d4a0.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://siruzosu.pbworks.com/f/bhojpuri_film_3gp_full_movie_download.pdf
    • http://mizunebapod.pbworks.com/w/file/fetch/144466734/33292300456.pdf
    • http://jotoxipigi.pbworks.com/w/file/fetch/144455022/81444328284.pdf
    • http://kipizasuzeda.pbworks.com/f/perfumes_the_a-z_guide_2018.pdf
    • http://niwomif.pbworks.com/f/lirolumi.pdf
    • http://naxenuve.pbworks.com/f/my_stupid_boss_2_lk21_indoxxi.pdf
    • https://uploads.strikinglycdn.com/files/804ab083-6e65-4c4f-bbfc-d6f347e9b99b/sex_education_season_2_episode_recap.pdf
    • https://uploads.strikinglycdn.com/files/0317b553-e9e8-48a0-8103-35501a2c567a/gloomhaven_spellweaver_guide_imgur.pdf
    • http://gosirata.pbworks.com/f/how_to_find_alien_containment_in_subnautica.pdf
    • http://xalomuzavege.pbworks.com/w/file/fetch/144459036/crossover_ccat_test_answers.pdf
    • http://sepaxebi.pbworks.com/f/fire_evacuation_plan_template_for_warehouse.pdf
    • https://uploads.strikinglycdn.com/files/04ad13d3-e0f8-410d-90a4-411f601a701d/thesaurus_of_scales_and_melodic_patterns.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000103e1.bin
c3eadc47db603c6336337255d29f7be172bde15adbfdd8a9d4f4f78df009a140
pdf-font-stream PDF embedded font (sfnt) at offset 0x103E1 5380 bytes
font_01_sfnt_off0001163f.bin
d6da702710e0a9000e7f460a2d7b73f2c16c8275eb1fe4593ebbe293eef777f6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1163F 11788 bytes