Malicious PDF — malware analysis report

Static analysis result for SHA-256 a77e108b5b334162…

MALICIOUS

PDF

77.3 KB Created: 2021-04-08 04:00:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: ca93ceb85da89430970767a33d7b664c SHA-1: 7ef27f96fbd8105ada2f6356c0d37d7acfdd02b6 SHA-256: a77e108b5b3341620f66b43b6b480d0cc2e97b1ec1492a5a9e0b352f5ab82094
146 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous external links, many of which point to disposable domains, suggesting a link farm or phishing attempt. The presence of a callback phishing lure heuristic indicates the document may be designed to trick users into calling a fraudulent support number. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution via the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=beats+solo+pro+wireless+noise+cancelling+headphones PDF link annotation
    • http://sotarebesowula.medianewsonline.com/handbook_of_landscape_archaeology.pdfIn PDF document text
    • http://design-kvartira.info/todos_los_libros_de_juego_de_tronos_en_espaolxc1qr.pdfIn PDF document text
    • http://legibovusapezo.mypressonline.com/wowamedegujosebinuwa.pdfIn PDF document text
    • https://cdn.sqhk.co/xujurovemu/HvjdjdZ/3d_surround_music_player_app_free_download.pdfIn PDF document text
    • http://tuzirawejaw.mypressonline.com/poverty_alleviation_definition.pdfIn PDF document text
    • http://garderob-podolsk.ru/12624515364mnvy3.pdfIn PDF document text
    • http://keepmaxi.space/nova_launcher_prime_apk_download_2020nwbb8.pdfIn PDF document text
    • https://cdn.sqhk.co/vagofedewat/IUnUMhe/final_fantasy_dimensions_2_apk_download.pdfIn PDF document text
    • https://cdn.sqhk.co/mopomotop/ifyR9ig/96361237698.pdfIn PDF document text
    • https://cdn.sqhk.co/vabalogu/jiKZicX/podcast_addict_apk.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/00e4a8e9-724f-4474-8d79-3de8ff4b3728/48435251420.pdfIn PDF document text
    • https://s3.amazonaws.com/lizuseguwix/38945293752.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3c01577b-e862-423e-999e-fd0178d137bf/95825579686.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/16c9eb0c-ebd0-4533-93b3-946eda003c32/bavapuzaxafadomal.pdfIn PDF document text
    • https://ca30e0e0-ecf2-44ab-b6a2-fe26291458be.filesusr.com/ugd/34e21e_3ba247b7377644c7809bd1cba6b382f7.pdf?index=trueIn PDF document text
    • https://a96990da-dd17-4b11-844c-aba2d588d1b6.filesusr.com/ugd/5e5e7b_df484209cc734c97b924cca090a8629e.pdf?index=trueIn PDF document text
    • https://0e75ab8e-f6a1-4360-bef2-1d94e06fde4e.filesusr.com/ugd/c0518c_06a24e2238494be8836d3fedbb6e34c9.pdf?index=trueIn PDF document text
    • https://20128683-61eb-4207-b985-d468b1a81fea.filesusr.com/ugd/0049ca_015cd99c625e48dfbc567d329720af93.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/9b8f6b82-b8d1-45f2-9f16-449b87a4a968/72409319787.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/afe94bce-f4ef-458e-98f5-f1aeb73a8708/acer_aspire_m3470g_motherboard.pdfIn PDF document text
    • https://s3.amazonaws.com/xetasif/dukabafe.pdfIn PDF document text
    • https://s3.amazonaws.com/buwosevax/how_to_change_2017_ford_focus_key_battery.pdfIn PDF document text
    • https://s3.amazonaws.com/pululusodogi/barakhadi_in_english_worksheets.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef48.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF48 5476 bytes
SHA-256: 194cb3c34e3fe221f1d03e37f1990a0bfb25a195a4801c7ce373c6b5856e7d15
font_01_sfnt_off000101f3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x101F3 11208 bytes
SHA-256: 629ce62ee499c9c45b2ca8ad3ee808b13558488190c499f9ca56991d68655d7e