Malicious PDF — malware analysis report

Static analysis result for SHA-256 d70f7ca63015c8e8…

MALICIOUS

PDF

62.9 KB Created: 2021-04-10 13:44:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 78895fc8f0c7e0d6cc4520b6b16b0fd4 SHA-1: e9063946dd8f1ba541daaa670c1d4e885ab7267b SHA-256: d70f7ca63015c8e8fd171575044f4b1e7b3b6591efc37871a5e6847d522c4c4a
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. Heuristics indicate it functions as a link farm, directing users to multiple distinct domains, one of which is `vectorcorp.net`. While no scripts were explicitly extracted, the PDF structure and the presence of external URIs suggest an attempt to redirect users to malicious content, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8592

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vectorcorp.net/sites/default/files/webform/resume/30106672217.pdf
    • http://cicatsalud.com/html/sites/default/files/webform/68038126183.pdf
    • https://www.jwico.com/sites/default/files/webform/47965191786.pdf
    • https://www.dgs-interparts.be/sites/default/files/64751185730.pdf
    • https://www.pharoxglobal.com/sites/default/files/webform/6669476875.pdf
    • https://www.mothercare.ro/sites/default/files/webform/resumes/77861868930.pdf
    • https://web.liderpapel.com/sites/default/files/webform/36759883892.pdf
    • http://russian-ice-spb.ru/sites/default/files/webform/files/loxigexaxezirizedud.pdf
    • http://www.pbttphtk.gov.my/sites/default/files/webform/kafavepovimurajubek.pdf
    • https://www.pharoxglobal.com/sites/default/files/webform/7322176875.pdf
    • https://europa-ts.ru/sites/default/files/webform/6529842099.pdf
    • https://extranet.blanchisserie-toulousaine-de-sante.com/sites/extranet.blanchisserie-toulousaine-de-sante.com/files/documents/justificatifs/pefusoxewirevujilo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/Uplcv/~3/zMnd8XtcwSM/uplcv?utm_term=alfred+prep+course+level+a+pdf
    • https://gradfutures.princeton.edu/system/files/webform/pelafo.pdf
    • https://minorsoncampus.princeton.edu/system/files/webform/libovonudipiguriteg.pdf
    • https://ubmemeaensoprod.s3.amazonaws.com/ifsec_international/call_for_papers/2021/03/gijewosatesozug.pdf
    • https://ubmemeaensoprod.s3.amazonaws.com/ifsec_international/call_for_papers/2021/03/60395266702.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c921.bin
9b7a46a60df4f0fcaa7ccc8d7f5165dce563c070557fe67b7d0eb0653cf6eb7d
pdf-font-stream PDF embedded font (sfnt) at offset 0xC921 5196 bytes
font_01_sfnt_off0000dae9.bin
085505f5b3516325835c049b10b47273739bcc3fccd2a71c49732050146cd898
pdf-font-stream PDF embedded font (sfnt) at offset 0xDAE9 10800 bytes