Malicious PDF — malware analysis report

Static analysis result for SHA-256 a080d444b26e8c31…

MALICIOUS

PDF

90.5 KB Created: 2021-04-25 04:46:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-10
MD5: 9ef1a57098ca62da948ca8239e946b28 SHA-1: 0c6f8d62a764571d0d52eb5680eb1f55e8732ea8 SHA-256: a080d444b26e8c31c139d006dcf3b3f21668f5e391afeb3d4c42f5fc26b7f521
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous embedded URLs, with one specifically pointing to a domain associated with phishing activity. The heuristic 'PDF_SEO_DISPOSABLE_LINK_FARM' indicates a non-clustered link farm on disposable hosting, further suggesting malicious intent. The ML classifier and ClamAV detection strongly indicate this PDF is malicious, likely serving as a lure to a phishing site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/strik?utm_term=how+to+fix+kenmore+microwave+door+switch PDF link annotation
    • http://trendmobile.ru/el_conde_de_montecristo_pelicula_completa_pelisplusrt14i.pdfIn PDF document text
    • http://sanatoriy-izumrudny.ru/1295525194010se2.pdfIn PDF document text
    • http://hargotel.xyz/kunis21wcz.pdfIn PDF document text
    • http://ideal-it.fun/67872579455ol7gr.pdfIn PDF document text
    • http://kunozoxutokusu.mygamesonline.org/51746668048.pdfIn PDF document text
    • http://ceter.xyz/duletenaviriwibawebvas4j.pdfIn PDF document text
    • http://labincom-med.ru/55772833753cm48w.pdfIn PDF document text
    • http://qiwi-wallet.online/how_to_fix_a_thermador_wall_oven5lpf6.pdfIn PDF document text
    • http://tamasolesodaj.mypressonline.com/79367255237.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/98709443-407e-4fd0-8365-70b5e4f2a746/casio_wave_ceptor_solar_powered.pdfIn PDF document text
    • http://nibemodida.myartsonline.com/holland_america_travel_agent_rates.pdfIn PDF document text
    • https://s3.amazonaws.com/minaxigevani/tuhan_agama_hindu.pdfIn PDF document text
    • http://dapufojutujat.atwebpages.com/adobe_signature_forgot_password.pdfIn PDF document text
    • https://s3.amazonaws.com/risalenefazozo/96523645057.pdfIn PDF document text
    • https://12c9c681-cafc-4f88-93da-cb6f471fd49a.filesusr.com/ugd/f09a9d_ae3e2b45c999435b847790503067a80d.pdf?index=trueIn PDF document text
    • https://3c3a732a-bc26-4be5-bc29-345d3dbc3408.filesusr.com/ugd/63a963_c6cebee85a0646dabc5cf51877aadf41.pdf?index=trueIn PDF document text
    • http://pekomuvave.myartsonline.com/gajuvamog.pdfIn PDF document text
    • https://f110cc6a-49d6-427c-9ab6-a3a4d323b004.filesusr.com/ugd/9e53d4_2ee5c996cad34795af4fc2ea09fbf112.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/818cbcd8-fc96-4ec8-ab3a-e7b7a224772c/formula_to_work_out_cylinder_volume.pdfIn PDF document text
    • https://s3.amazonaws.com/lomogas/how_to_assemble_a_12_ft_trampoline.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e113e265-458c-4e56-bcd8-14ec2eb9eb8d/ashrae_handbook_1997_free_download.pdfIn PDF document text
    • https://f3ea461b-95fd-44cf-949c-5afda193840f.filesusr.com/ugd/a48928_21f25bf494084411bb6aaaf16421fb8a.pdf?index=trueIn PDF document text
    • https://4f65501f-cdae-4966-b9db-49b15ad9d196.filesusr.com/ugd/52b593_868a61aefdb8402fa6004c9e6924ef26.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/rerinago/angular_directive_template_attribute.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/32290f67-1ce1-40e5-9adb-27410319bd50/x_plane_10_flight_simulator_mod_apk_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9c2ba236-4153-48ba-9cfe-8ca18fdce5cd/the_odyssey_study_questions_answer_key.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012336.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12336 5476 bytes
SHA-256: a79659a06247c615f203b19e08f832417c2fe53d76b75b40928d5f56e8684ebf
font_01_sfnt_off000135c6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x135C6 11260 bytes
SHA-256: 747d85c0710ee82a9ab63520792d88f451574a03dbc4359707e73f7bb2725530