Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd1277e311a25d8e…

MALICIOUS

PDF

66.6 KB Created: 2021-03-23 01:22:00 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dfd468a3a5f605188fa745f05db247a3 SHA-1: 34e802b9869860abc5e87c65de4d6f276dc358ba SHA-256: bd1277e311a25d8ef0066cddbde3a3ab419afb3c0eb07f4c50f0c0696589cb25
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, many pointing to disposable hosting, and is flagged as a link farm. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or distributing further malware. The presence of embedded JavaScript, though not explicitly detailed in the provided evidence, is a common technique for exploiting PDF vulnerabilities and initiating malicious actions.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9716

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/aws?utm_term=self+reliance+meaning+in+english
    • https://kiwepuzimogavuf.weebly.com/uploads/1/3/0/7/130776877/5478348.pdf
    • http://pibarulajido.getenjoyment.net/64169957043.pdf
    • http://gopusoduj.mygamesonline.org/definition_of_brand_awareness.pdf
    • https://cdn-cms.f-static.net/uploads/4408997/normal_602f16334b339.pdf
    • http://nopuvobetag.mygamesonline.org/definition_of_agroforestry.pdf
    • http://zitarekatinupas.sportsontheweb.net/55881784914.pdf
    • https://cdn-cms.f-static.net/uploads/4470962/normal_6029341415491.pdf
    • http://rixorevu.getenjoyment.net/politojovedo.pdf
    • https://nixunirebexif.weebly.com/uploads/1/3/0/7/130776125/zetabasumenefoj.pdf
    • https://vofitikasu.weebly.com/uploads/1/3/1/8/131871658/f799c9794.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://wudemexa.myartsonline.com/59325195468.pdf
    • https://b913155d-2712-4fd4-bcc6-651970a8c456.filesusr.com/ugd/e39924_9915cf9872c5459fabaf16b3a80d51cc.pdf?index=true
    • http://nufiwimuzobo.onlinewebshop.net/wotajirugulugijematado.pdf
    • https://b5b764bc-4fc6-48d7-9a4b-423a4d05f225.filesusr.com/ugd/3f2390_b57e77d7aacb4ee096d6e5265d08ec2d.pdf?index=true
    • https://s3.amazonaws.com/sowewazulejewi/how_do_i_know_if_ue_boom_is_charging.pdf
    • http://roporuti.onlinewebshop.net/alipay_logo.pdf
    • https://s3.amazonaws.com/tufujifinobiro/what_is_group_development_in_social_work.pdf
    • https://8569cc17-8b2a-4187-ace0-95b0550b99f0.filesusr.com/ugd/d6eede_423b3a9ba3794cc9960fdcf55cdb0c2c.pdf?index=true
    • https://s3.amazonaws.com/jinabom/report_definition_in_activity_pega.pdf
    • http://forojiwimudobo.atwebpages.com/how_to_become_a_better_communicator.pdf
    • https://s3.amazonaws.com/saxefi/giving_tuesday_email_templates_mailchimp.pdf
    • https://s3.amazonaws.com/mujesogi/20104276263.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e878.bin
721cc2fdd3dc595dcb3ceb283710897e6e3f946895107a6db3eba0a731c1121f
pdf-font-stream PDF embedded font (sfnt) at offset 0xE878 5684 bytes
font_01_sfnt_off0000fc55.bin
3ce1bf1a9d4e9b0000adb58a6983656f0014cae247f026b30e755f7aef084461
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC55 5396 bytes