Malicious PDF — malware analysis report

Static analysis result for SHA-256 df8af1ec58d7590a…

MALICIOUS

PDF

75.8 KB Created: 2021-09-13 01:38:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 24d49a2d50d190e4003da775bb71f44c SHA-1: 4bae7af4eec36d7ec7474c71fa6f6443cfca4717 SHA-256: df8af1ec58d7590ae11d4345ce3da37e86213d105cef9cc3952c4f9d2e171687
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs, with a high heuristic firing indicating it functions as a link farm on disposable hosting. The ClamAV detection and ML classifier also flagged this PDF as malicious, specifically as a phishing trojan. While no scripts were directly extracted, the nature of the embedded URLs suggests an attempt to redirect users to malicious sites, likely for phishing or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7561

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tutaylamhet.com/storage/ckfinder/files/66662746363.pdf
    • https://canevastoilestjean.com/upload/editor/file/dikuro.pdf
    • http://thanglong.vn-greenenergy.com/ckfinder/userfiles/files/mazegidabufabonisima.pdf
    • http://alvasari.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613b9c63d91d0---51439115043.pdf
    • https://deesudcoolingtower.com/userfiles/file/62569263799.pdf
    • https://best-of-geldanlagen.de/userfiles/file/tilojuxaxotofegisog.pdf
    • http://ke-sen.com/userfiles/file/1630623819.pdf
    • http://tuning-zone.eu/userfiles/file/jibekogekozuko.pdf
    • http://savalis.ru/userfiles/file/31793479495.pdf
    • http://c2mag.com/wp-content/plugins/formcraft/file-upload/server/content/files/16130218c03753---dasisilaronozosovamivoxes.pdf
    • http://autosoftware.company/autoresponders_images/files/virabiraponogadakos.pdf
    • http://amicissiapiemonteisa.it/userfiles/files/58517295071.pdf
    • https://griby.biz/ckfinder/userfiles/files/80496484571.pdf
    • https://asoriofrio.org/ckfinder/userfiles/files/48638927444.pdf
    • http://goldenteriyaki.com/uploads/files/45356833535.pdf
    • https://basundharamart.com/userfiles/file/73672984939.pdf
    • http://www.pilatesyoga.hr/files/files/ritixodekukume.pdf
    • http://phubozena.pl/userfiles/file/mukubapijilonularagim.pdf
    • http://tunesistudio.eu/userfiles/files/99073771763.pdf
    • http://dsagco.com/Upload/file/noberokalanililapoxe.pdf
    • http://intertribo.sk/files/siturodukelirisalifo.pdf
    • http://hk-keber.de/images/file/49572146547.pdf
    • http://www.agot.pl/upload/file/siduket.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/cv9VXjIrmdE/uplcv?utm_term=best+action+mobile+games+2020
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d7bb.bin
3c28ed7a710000e7a7f578bc1674a517a6cd5ca87dadf3e0e6b29bf37fc66fe1
pdf-font-stream PDF embedded font (sfnt) at offset 0xD7BB 17528 bytes
font_01_sfnt_off00010598.bin
98727b95e31aea1159c7f7a19fbf0f2c0794338a28e19ad13f462dcf440d0df1
pdf-font-stream PDF embedded font (sfnt) at offset 0x10598 10908 bytes