Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f8a9b4a9f01d8cb…

MALICIOUS

PDF

82.2 KB Created: 2021-03-18 00:42:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-02
MD5: 495209f31487db9ae43915d3412897fc SHA-1: b1dc9d7fbdaf3403770d20776a9c5d3a83364f60 SHA-256: 9f8a9b4a9f01d8cbfac98165c5d5384dfe881f234b4747fbb7886c098737eba8
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are SEO-optimized and point to other PDF documents, indicating a link farm strategy. The ClamAV detection and ML classifier further support its malicious nature. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to redirect users to malicious content, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=ubqari+magazine+september+2020+pdf+download PDF link annotation
    • http://sowopezamiw.medianewsonline.com/29731157309.pdfIn PDF document text
    • https://vizegibog.weebly.com/uploads/1/3/4/4/134458583/a3fde3458.pdfIn PDF document text
    • http://vizionsmc.net/982205239758rc65.pdfIn PDF document text
    • https://tevukebejesa.weebly.com/uploads/1/3/2/6/132695492/bc8474fbdc0f211.pdfIn PDF document text
    • http://jekenufakewe.mypressonline.com/68627528420.pdfIn PDF document text
    • http://healthyforczechrepublic.site/toyota_camry_trd_0-60_time6p3vr.pdfIn PDF document text
    • https://noserosajegupa.weebly.com/uploads/1/3/1/4/131453720/46ad47a.pdfIn PDF document text
    • http://bumaga.bz/avadhuta_gitarie7h.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://s3.amazonaws.com/wokesabisevo/constructing_angle_bisectors_and_perpendicular_bisectors_worksheet.pdfIn PDF document text
    • https://s3.amazonaws.com/nafoxuda/passport_application_form_online_tanzania.pdfIn PDF document text
    • https://s3.amazonaws.com/wivunonovef/70691234927.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cec07e00-d171-4ad7-8ddd-d58db8e9076e/nufitosarazixoxoj.pdfIn PDF document text
    • https://s3.amazonaws.com/zemigiduwagafu/us_guided_needle_biopsy_breast.pdfIn PDF document text
    • https://s3.amazonaws.com/peveziwoguxuzam/classifying_animals_into_vertebrates_and_invertebrates_worksheet.pdfIn PDF document text
    • http://rukosivujuxu.atwebpages.com/piwozodemanibejovu.pdfIn PDF document text
    • https://s3.amazonaws.com/zoromexemuzid/50790866984.pdfIn PDF document text
    • https://s3.amazonaws.com/turip/spelling_bee_list_2020.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/67d1fe3c-d331-48e9-be14-107bb033d505/72712200932.pdfIn PDF document text
    • https://s3.amazonaws.com/podawakumepewez/amniocentesis_test_report_sample.pdfIn PDF document text
    • https://s3.amazonaws.com/gavexilatuvitaz/jusugefebet.pdfIn PDF document text
    • http://lupixopuvir.onlinewebshop.net/angel_sigils_supernatural.pdfIn PDF document text
    • https://s3.amazonaws.com/dinilederu/tenugosuzi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/93cb8db0-cff1-41f8-91c5-167e776f2c37/the_human_body_an_orientation_notes.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a1bce051-1f3b-4f36-b0fa-f1159282aada/resumen_de_cien_aos_de_soledad_de_gabriel_garcia_marquez_por_capitulos.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d84b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD84B 6032 bytes
SHA-256: 2b5196e010a6f01897f12b298a4cd351d8a784844c739dca7836e2b9595b7901
font_01_sfnt_off0000ecce.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xECCE 2604 bytes
SHA-256: 5fd53e2058c4f5d98b70161d670f1e42036942552fef68ac845a5e47e2d7f715
font_02_sfnt_off0000f7f0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF7F0 11348 bytes
SHA-256: 36967640a19edc4546b13f775b29ad69444ab43e1545f27c93207347ef60efb1
font_03_sfnt_off00011d36.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11D36 18104 bytes
SHA-256: 01319aa4ded363944cd41e84055cf5699ad285532c28174002c851fb664427dc