Malicious PDF — malware analysis report

Static analysis result for SHA-256 a66f95abf0a2c867…

MALICIOUS

PDF

65.9 KB Created: 2021-03-25 09:57:48 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 01e4d1a2fa4efc1b0d64bef304a1598f SHA-1: 2551038946dbf7e409722683502d70b1e66b2552 SHA-256: a66f95abf0a2c867dc80597ea45e9d8343db9f780609c5187db80f8a36b42700
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of embedded links, many of which point to known malicious redirector infrastructure or unknown domains. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' and 'PDF_SEO_LINK_FARM' indicate a strong attempt to direct users to potentially harmful sites. While no scripts were explicitly extracted, the nature of the embedded links suggests a phishing or scam attempt, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/award?keyword=c+interview+questions+pdf In PDF document text
    • http://cheatyou.site/john_deere_320_skid_steer6zci2.pdfIn PDF document text
    • http://cooldomen.space/boruvibezoderodoj71jt.pdfIn PDF document text
    • http://gromstroy.com/workplace_safety_and_insurance_appeals_tribunal_decisionsghqtt.pdfIn PDF document text
    • http://tezibif.mygamesonline.org/pumozuzevonenuregapi.pdfIn PDF document text
    • http://lopixerirerenex.mywebcommunity.org/cupid_and_psyche_by_lucius_apuleius.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://6d1a2d78-ebd2-4140-94a0-411197be5b5f.filesusr.com/ugd/88ff89_289fd5f92cf342df801f79074e0edea9.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/acabbe0c-127c-4d8b-a062-67468791f472/panasonic_service_phone_number.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/da60ad21-227b-4e1e-8d74-bb3d79abb8f9/80155767568.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/64254ff6-a613-4d13-ae22-4a2903671406/lasamafininureforidavi.pdfIn PDF document text
    • https://ad9e3d1f-bb22-46ca-892e-b6aa3325a756.filesusr.com/ugd/837d34_8c84d87ef4d6464d96123c37b13335a6.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/fosagoba/chatiw_android_app.pdfIn PDF document text
    • https://s3.amazonaws.com/wekibik/fomojokimijuwudez.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/840484b7-b30a-45b1-97a2-f564c49f74cf/fisher_paykel_dishdrawer_technical_support.pdfIn PDF document text
    • https://s3.amazonaws.com/zopenave/14674387386.pdfIn PDF document text
    • https://s3.amazonaws.com/kumasala/gaxemanerut.pdfIn PDF document text
    • https://s3.amazonaws.com/rimejiguvif/titration_of_hcl_and_naoh_lab_report.pdfIn PDF document text
    • https://s3.amazonaws.com/kaxukok/study_bible_free_download_for_android.pdfIn PDF document text
    • https://s3.amazonaws.com/fuzafuzeruwit/el_camino_del_artista_completo.pdfIn PDF document text
    • https://s3.amazonaws.com/zalisujezajaje/91067518551.pdfIn PDF document text
    • https://s3.amazonaws.com/niwotipugonuvoz/supenaxiwomi.pdfIn PDF document text
    • https://18b09f4e-de4d-4c1b-9fe6-be55c63b1c00.filesusr.com/ugd/cd81e9_657c381b91ba45cd8cbf18fed75006a4.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/penale/what_is_the_value_of_gas_constant_r_in_l_atm_mol_k.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c6b4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC6B4 4976 bytes
SHA-256: 1d429079cf278768f8dd8e4aeae78b80e44d72ba491d208886b8ac715f2915fe
font_01_sfnt_off0000d7c4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD7C4 10116 bytes
SHA-256: 35018f49d189436820fce9d5ff988195470233de52cb136a6b244c9548d72b23