Malicious PDF — malware analysis report

Static analysis result for SHA-256 e887814165977a4f…

MALICIOUS

PDF

76.0 KB Created: 2021-09-12 10:24:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 8a72c6b8cc74a3c97c5a1715d444b80b SHA-1: 121b965f88604f5e49b65f422059890bb2c81913 SHA-256: e887814165977a4f63f0cee6f8162c5b4442af87e85bfb2749c8af68104cb7dc
134 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF_JS heuristic indicates embedded JavaScript, which is a common method for executing malicious code within PDF documents. The numerous PDF_URI firings, coupled with the ML classifier's high score, suggest the JavaScript is likely used to redirect the user to malicious sites. The ClamAV detection further confirms the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9948

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mikailang.net/userfiles/file/20210906003826_732657658.pdf
    • https://senzedigicraft.com/wp-content/plugins/super-forms/uploads/php/files/86d8cd9f308cd398ee6fdb7640a23929/jokolibuwasipowuxome.pdf
    • http://eggtesting.com/admin/uploads/file/39238052515.pdf
    • http://www.mbk-montage.nl/ckfinder/userfiles/files/54962784143.pdf
    • http://vladekoservis.ru/files/88889215595.pdf
    • http://gavinlawoffice.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/bokurofazuwosawom.pdf
    • http://billagelaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/rezimuxexubabalugejorul.pdf
    • http://kuryakyn.ru/userfiles/file/29309695587.pdf
    • https://b2b-intelligence.it/uploads/file/31817027111.pdf
    • http://guojingmall.com/userfiles/file///xubijewi.pdf
    • http://andreagarciam.com/wp-content/plugins/formcraft/file-upload/server/content/files/161386a0da0d12---24472950150.pdf
    • http://sicilalluminio.it/userfiles/files/13819962518.pdf
    • http://winso.tw/userfiles/file/janixused.pdf
    • https://fa-vietnam.com/webroot/img/files/64418694375.pdf
    • https://learnrkbin.jugalbandiresearch.com/ckfinder/userfiles/files/zitagesijixovamofugof.pdf
    • http://cps-mbstu.edu.bd/app/webroot/js/ckfinder/userfiles/files/65556797841.pdf
    • http://laboratoriologos.it/userfiles/files/60518366248.pdf
    • http://kopdesign.nl/userfiles/file/giviloxog.pdf
    • http://barahi.com/assets/userfiles/files/64928415428.pdf
    • http://tradotel-riviera.com/file/6860357285.pdf
    • https://kheops-so.fr/ckfinder/userfiles/files/gopasegosov.pdf
    • http://jimsclub.net/new/board/img_tinfo/file/20210909081329.pdf
    • http://qualityfirstservices.pro/testingsites/advantage_aviation/assets/media/file/kaxupopojefoximet.pdf
    • https://efficimm.fr/userfiles/files/13264374610.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BkSY9tpko7c/uplcv?utm_term=strike+back+putlocker
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c24c.bin
725b5b1818cec6ff1e7e23f9c2f2d77c2a8e6c79037a516150c1240f5318010e
pdf-font-stream PDF embedded font (sfnt) at offset 0xC24C 18260 bytes
font_01_sfnt_off0000f168.bin
14ebe56b50f4076b36ef11837a750e0d4dfdc7fe008e0deafafb39b70d7a69f5
pdf-font-stream PDF embedded font (sfnt) at offset 0xF168 10500 bytes
font_02_sfnt_off0001093a.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1093A 16792 bytes