Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8522f8bbf7f59b0…

MALICIOUS

PDF

77.5 KB Created: 2021-02-14 13:28:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 81ba171619faaf88924f4a61d48d78ea SHA-1: d0a6f66057de63e5a9ff81c374fe66ff97738517 SHA-256: d8522f8bbf7f59b0aa6634eef72d3eef2ee021fef3a3e88e23e3439fe28d1f0b
226 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains a large number of external links, many hosted on disposable domains, indicating a link farm designed to direct users to potentially malicious content. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' suggests this PDF might be part of a chain where a password is provided to decrypt a subsequent payload, often used to bypass gateway security. The ClamAV detection and ML classifier further support its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/123?utm_term=ptc+que+pagam+em+euros PDF link annotation
    • https://wijuluberaselak.weebly.com/uploads/1/3/4/0/134016921/33ad6c27.pdfIn PDF document text
    • https://fogufufizanalu.weebly.com/uploads/1/3/0/8/130813948/78c5adea0a3c.pdfIn PDF document text
    • https://jowavuzawevubab.weebly.com/uploads/1/3/2/3/132303017/6009608.pdfIn PDF document text
    • https://ribofefafuf.weebly.com/uploads/1/3/4/7/134770843/6003040.pdfIn PDF document text
    • https://cdn.sqhk.co/fabozesemi/OifhdTv/jixafugazelemegefulakus.pdfIn PDF document text
    • https://cdn.sqhk.co/zezoxomop/hvmGhib/labexazirefokurivomen.pdfIn PDF document text
    • https://dexasarejujevi.weebly.com/uploads/1/3/1/4/131454537/menewuruzila-xafopirikesozo-busuwim.pdfIn PDF document text
    • https://nudabixe.weebly.com/uploads/1/3/4/5/134505388/bc88d46d861a75.pdfIn PDF document text
    • https://cdn.sqhk.co/gujurolekuma/gjA1gep/alone_pics_for_whatsapp_dp.pdfIn PDF document text
    • https://cdn.sqhk.co/togodawexu/Dyijjay/puppy_wallpaper_free_download_for_mobile.pdfIn PDF document text
    • https://cdn.sqhk.co/gufemazibafi/gLFWiXh/f_stop_gallery_apk_pro.pdfIn PDF document text
    • https://dibalinelig.weebly.com/uploads/1/3/1/3/131380687/mosetefubonisusixil.pdfIn PDF document text
    • https://cdn.sqhk.co/putizimetiwe/helihfP/23978945501.pdfIn PDF document text
    • https://cdn.sqhk.co/luvutagawata/hALjjhf/feisty_pets_mini_cat.pdfIn PDF document text
    • https://nulivuxod.weebly.com/uploads/1/3/0/7/130776854/bifesofaxoru_berowa_jujuko_libubojomozep.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/zeworibuzoza/busy_teacher_grammar_worksheets.pdfIn PDF document text
    • https://s3.amazonaws.com/tudawufed/somorogigipanoxibifotu.pdfIn PDF document text
    • https://s3.amazonaws.com/zetituri/tosetevoku.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d723.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD723 5348 bytes
SHA-256: ba60f7ee1c363bd9b394880608b59c97e61444614e32078a2984f0e7eeb3ac7d
font_01_sfnt_off0000e941.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE941 13360 bytes
SHA-256: eae6edd1e505c8e603296d02af8c7fab60d8349c1c5f4620da303906ec03b4e6
font_02_sfnt_off00011261.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11261 16144 bytes
SHA-256: 764fe263e68fd20aff2bbd96e69f5a400d440299d02096befa162391f913c7cf