Malicious PDF — malware analysis report

Static analysis result for SHA-256 9aac84aa6fb0395a…

MALICIOUS

PDF

162.1 KB Created: 2021-03-09 04:20:08 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-22
MD5: 1ce0ba24df23fbad3f0433980781b963 SHA-1: 873c1f906ef8804254abacaa3b0bf50e25d59666 SHA-256: 9aac84aa6fb0395a199bac2d78ab7b39ac2a65c366fbad48a1390e3c33b2383f
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was flagged by multiple heuristics, including ML_NYX_PDF_MALICIOUS and SE_BRAND_CREDENTIAL_PHISH, indicating a high likelihood of malicious intent. The presence of numerous external URIs, many pointing to disposable hosting or redirectors, supports the phishing lure. The ClamAV detection further confirms its malicious nature, classifying it as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9961

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Brand-impersonation credential phishing lure critical SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: action link to abused redirector https://gifaxopolipo.weebly.com/uploads/1/3/0/7/130739444/9457583.pdf.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=urahara+bleach+bankai PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4423780/normal_5fd10bea4bdff.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4403685/normal_5fc8c38b3c1c8.pdfIn PDF document text
    • https://gifaxopolipo.weebly.com/uploads/1/3/0/7/130739444/9457583.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4405644/normal_5fe2bfacc0994.pdfIn PDF document text
    • https://fugebigejajifad.weebly.com/uploads/1/3/1/4/131406613/kanaxuvo.pdfIn PDF document text
    • https://cdn.sqhk.co/dixobiwi/TN6giic/21753517414.pdfIn PDF document text
    • http://xejopegig.mypressonline.com/what_workouts_do_marines_do.pdfIn PDF document text
    • https://rinajota.weebly.com/uploads/1/3/4/7/134714435/marojubukefemimako.pdfIn PDF document text
    • https://cdn.sqhk.co/samofetob/hdGSmat/ludo_neo_classic_for_pc.pdfIn PDF document text
    • https://cdn.sqhk.co/livatunozasu/KGVjfLw/zinotovajovajuvujuzexixar.pdfIn PDF document text
    • https://cdn.sqhk.co/tefupudoma/XPieMic/35141906537.pdfIn PDF document text
    • https://bijejosuti.weebly.com/uploads/1/3/1/6/131637047/7114a9.pdfIn PDF document text
    • https://ribigitapupag.weebly.com/uploads/1/3/4/8/134887221/vanupofomu_polejigane_lutovaruxaj.pdfIn PDF document text
    • https://nogapixefakul.weebly.com/uploads/1/3/4/5/134590999/xepokubedenujij-suteweb-rovelobilu-kixarokefikasul.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420239/normal_5fd5f0cf68fb5.pdfIn PDF document text
    • https://muwikilakejo.weebly.com/uploads/1/3/4/5/134519857/zenekifapeluvos.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://wulibazosuxib.onlinewebshop.net/what_is_a_comptia_a_certification.pdfIn PDF document text
    • http://tiluxusimutine.atwebpages.com/dell_r710_server_rack_size.pdfIn PDF document text
    • https://s3.amazonaws.com/kelukakeb/50387068951.pdfIn PDF document text
    • http://bifovigavij.myartsonline.com/how_do_i_start_bitcoin_trading_for_beginners.pdfIn PDF document text
    • http://nabenejajoko.myartsonline.com/3411851001.pdfIn PDF document text
    • https://s3.amazonaws.com/sifawekujiki/examples_of_active_and_passive_voice_in_present_perfect_tense_negative.pdfIn PDF document text
    • https://s3.amazonaws.com/limewub/tilibalopibubaponovono.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001f02a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1F02A 19208 bytes
SHA-256: a0deede010abff59c1d37cb45c57e5e28f75dd85ac1f869c4d9aedb5a2e5544f
font_01_sfnt_off00022c35.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x22C35 4904 bytes
SHA-256: 21f1ce4117d62203f95a01a05e18a96e603716201549f9250534a32c8a0acf9f
font_02_sfnt_off00023cde.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x23CDE 10736 bytes
SHA-256: 41015812097e471f9fa415500f452d486c38905be5e3977d84d9a1e200774b1a
font_03_sfnt_off000261da.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x261DA 16832 bytes
SHA-256: b2262f5e888b589ea317d9f474487b27028cebd073fc4280985b145c3962df5e