Malicious PDF — malware analysis report

Static analysis result for SHA-256 c9064728d3ce4dad…

MALICIOUS

PDF

97.8 KB Created: 2021-03-14 18:49:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 97f65317cf604e6388c711e84435dbb6 SHA-1: 7b43a4b416fde49b9af72cec7399ca5bcd8f07f5 SHA-256: c9064728d3ce4dad37b352800c1cfa0d9f69a06dc57ae52d3bd9967b300d33a6
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, with a significant heuristic identifying it as a link farm on disposable hosting. The ML classifier and ClamAV detection strongly indicate malicious intent. The presence of external URIs and the nature of the heuristics suggest the document's primary purpose is to redirect users to potentially harmful sites, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/123?utm_term=font+bebas+kai+normal
    • http://godubumoze.iblogger.org/50707360018.pdf
    • https://cdn-cms.f-static.net/uploads/4419001/normal_601b11ffcf33a.pdf
    • https://static.s123-cdn-static.com/uploads/4488809/normal_600839d8a3692.pdf
    • http://zagavogafewakud.iblogger.org/4x6_lined_index_card_template.pdf
    • http://bipogumaguwe.22web.org/99592097530.pdf
    • http://denarop.22web.org/xutakusabiwowapefisi.pdf
    • https://cdn-cms.f-static.net/uploads/4373998/normal_5fd75cf3bcbab.pdf
    • https://static.s123-cdn-static.com/uploads/4501991/normal_5ff1d515bf382.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://gozadowosib.rf.gd/47977168135.pdf
    • http://xavitemis.rf.gd/67018282661.pdf
    • http://lamekukibudinos.epizy.com/lozuwokozowufitidet.pdf
    • https://4c72699b-aa2e-4dc8-8bd5-1a54e8f938a6.filesusr.com/ugd/f3cb45_bdd12f28ae1e4b16a3fb14fb523b55a8.pdf?index=true
    • https://17851959-1482-4b49-8222-7b7b0c628459.filesusr.com/ugd/3cb679_9340461bbec84d85a00cdb948a83a26d.pdf?index=true
    • https://29ce6865-365c-47c4-9f0a-635d6f965865.filesusr.com/ugd/0d6b77_b78ba4252b0c452b89c8cebab998eea0.pdf?index=true
    • https://247e77cc-5367-4382-8586-7c5891409f42.filesusr.com/ugd/2dbf5a_d0abfc47e1d849e2880cf3bc6c85a0cd.pdf?index=true
    • http://redepulevinevux.epizy.com/wejuf.pdf
    • http://fazetotunoju.epizy.com/40187539806.pdf
    • https://8ed62699-7d02-4439-b935-4286882ef7d4.filesusr.com/ugd/229b11_2c64344a4cff4993897958008ea53bed.pdf?index=true
    • https://7133fc40-0b9c-4701-b953-e7fafc934b44.filesusr.com/ugd/70a38d_caa73868cf014eba833cc00394c592e5.pdf?index=true
    • https://104e0e48-a4c2-4a03-8647-06ef64d4e6ac.filesusr.com/ugd/e2c6c1_644ee680fb534514a142703c2f5e57bf.pdf?index=true
    • https://f6ea5e03-7e7c-4dce-82ee-fd5d223759ef.filesusr.com/ugd/d203ad_1a371bdce89b4d1ab864c3283170a347.pdf?index=true
    • https://e06e8306-d71e-4c92-aa1b-e8c52eeb44cb.filesusr.com/ugd/bc4951_08e7bf14d2434beaa3c4581d5ea2a508.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed6e.bin
238c5b72f5c7fef710cdec0cf1a5018f968c4586509cab8e031f2177a6ea88f8
pdf-font-stream PDF embedded font (sfnt) at offset 0xED6E 4988 bytes
font_01_sfnt_off0000fe54.bin
47ec501fc80d3885d3c787db5948c424134203855bebe432da923855862a6ba4
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE54 48852 bytes
font_02_sfnt_off00015fd6.bin
dd97c73ae82d1663306a7af13120dd2505ff84a8527f258375f4500ef1c8ac1e
pdf-font-stream PDF embedded font (sfnt) at offset 0x15FD6 17756 bytes