Malicious PDF — malware analysis report

Static analysis result for SHA-256 97a9333321db31f7…

MALICIOUS

PDF

83.8 KB Created: 2021-02-07 11:08:48 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-23
MD5: 84f60935f926cc1d72a1d290324c1260 SHA-1: 451103ea2cec863d9cae18fec99f565006acfa98 SHA-256: 97a9333321db31f706e835a1619bb843fc4b83c7a3d922ba71aa6473c3edb99c
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for phishing or redirecting users to malicious sites. The 'PDF_SEO_LINK_FARM' heuristic indicates a large number of outbound links, suggesting a link farm or redirection scheme. ClamAV detection and ML classification confirm maliciousness, with the sample identified as 'Pdf.Phishing.Trojan'. While no scripts were explicitly extracted, the presence of embedded URLs and the overall structure point towards a phishing or malicious redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/123?utm_term=geometry+chapter+8+test+pdf PDF link annotation
    • https://rokubupudila.weebly.com/uploads/1/3/1/8/131856034/beropovomo.pdfIn PDF document text
    • http://gulidomirebo.22web.org/zigovevomedejiwuxule.pdfIn PDF document text
    • https://cdn.sqhk.co/kegufamop/iiCghhg/motorcycle_rider_3d_model.pdfIn PDF document text
    • http://buzovanukoziba.22web.org/gebawasukofog.pdfIn PDF document text
    • https://cdn.sqhk.co/jufebarur/heHp8tR/wood_hit_throwing_knife_targets.pdfIn PDF document text
    • https://zujujoweb.weebly.com/uploads/1/3/5/2/135297083/rezuwexurakoz.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://kovefevejafuk.epizy.com/51279719043.pdfIn PDF document text
    • http://maxuzenikofi.epizy.com/copd_treatment_guidelines_uptodate.pdfIn PDF document text
    • https://s3.amazonaws.com/woxojuxafopuv/contoh_report_text_beserta_pembagian_strukturnya.pdfIn PDF document text
    • https://s3.amazonaws.com/nazekisigiduz/jadoke.pdfIn PDF document text
    • https://s3.amazonaws.com/wegemebufojafak/epping_nh_police_reports.pdfIn PDF document text
    • https://s3.amazonaws.com/tufitijinexu/free_tileset_2d_platformer.pdfIn PDF document text
    • http://jevabatogi.rf.gd/85160382178.pdfIn PDF document text
    • https://s3.amazonaws.com/patilawasu/femme_fatale_tv_series_episode_guide.pdfIn PDF document text
    • http://jizozekawa.epizy.com/gubizafosi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d8f7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD8F7 5324 bytes
SHA-256: c400f1a22a0d11ade4d257609c673cef5c1e7112477b229123d9e7d5fdadd990
font_01_sfnt_off0000eb16.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB16 15952 bytes
SHA-256: 15a729a2b5b50a37d005d88f063ef3427435c27eecb158cf5ab1c6251c190d64
font_02_sfnt_off00011cfa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11CFA 16092 bytes
SHA-256: 9af6fc3bf9d751f70540aea0fa47faa159a3604992cda23d2adcda3ffc5346b2
font_03_sfnt_off000131c1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x131C1 4324 bytes
SHA-256: d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378