Malicious PDF — malware analysis report

Static analysis result for SHA-256 c64d67ffe77bba62…

MALICIOUS

PDF

78.5 KB Created: 2021-03-27 10:50:39 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fd59f0548c19596795ef902e21c8ce9a SHA-1: ebdb2f658d760dd57971c9c6dfaf4e7282681ed8 SHA-256: c64d67ffe77bba627f7da004a92c88e0e98c4a49dd250197fd37825b50f494a9
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs, with one specifically pointing to a domain associated with phishing and malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. The document body, though heavily obfuscated, suggests a lure related to 'market segmentation analysis', likely to trick users into clicking the malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/award?keyword=market+segmentation+analysis+pdf
    • http://cyberghost.store/bhagavad_gita_full_book_in_gujaratiia56a.pdf
    • http://wersita.fun/formula_para_convertir_de_pulgadas_a_mmj59ej.pdf
    • http://sibatike.getenjoyment.net/ad_hoc_wireless_networks_vtu_notes.pdf
    • http://firstreadersclub.com/microsoft_excel_spreadsheet_examplesbcr6s.pdf
    • https://static.s123-cdn-static.com/uploads/4381543/normal_5ff578cb22c34.pdf
    • http://mikrotikwizard.com/jiseloxmqtmt.pdf
    • https://cdn-cms.f-static.net/uploads/4501206/normal_602c43950f0a6.pdf
    • http://kivolugog.mypressonline.com/xenifisojevor.pdf
    • http://50off.pro/world_map_with_countries_and_states_labelednqukg.pdf
    • http://zokiwedilar.mypressonline.com/ecers_3_book_download.pdf
    • http://megidexabaror.mywebcommunity.org/60450009475.pdf
    • https://cdn-cms.f-static.net/uploads/4446921/normal_60117638616b4.pdf
    • https://static.s123-cdn-static.com/uploads/4446502/normal_60034ca544fdb.pdf
    • http://tatemegedes.sportsontheweb.net/study_of_body_language_and_facial_expression.pdf
    • https://cdn-cms.f-static.net/uploads/4445129/normal_5fd5f2a3570cb.pdf
    • https://static.s123-cdn-static.com/uploads/4403560/normal_5fdf2bc2e29b5.pdf
    • http://modozadubop.mywebcommunity.org/taxawoxavib.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://gagolabirej.atwebpages.com/90711222274.pdf
    • http://kakavogulogij.onlinewebshop.net/88062615704.pdf
    • https://6196a4e6-b3b5-4a85-a139-4ec84e0a53d9.filesusr.com/ugd/d01287_4ef818c0a626446d8fa23086313f2c28.pdf?index=true
    • http://vigavanoxe.onlinewebshop.net/muvozedunarebigetuxif.pdf
    • https://dfabac9c-3a78-4d86-b112-ccf1750024e9.filesusr.com/ugd/b46e2f_ba8b0a2cb9924ab4967eb1659a5b0fee.pdf?index=true
    • http://fanalejowegop.atwebpages.com/how_to_find_bounded_above_or_below.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5b8.bin
c8e7417fc43df46a4994593e5ef320384758ee0e2f170cf289593c9e17f326f8
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5B8 5532 bytes
font_01_sfnt_off00010893.bin
616840d86e981af40c6efc843a7b48b46c70d5417cdd6a3a4c2a24f912634499
pdf-font-stream PDF embedded font (sfnt) at offset 0x10893 10480 bytes