Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8baa325fabcc080…

MALICIOUS

PDF

72.8 KB Created: 2021-03-19 12:11:08 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f633853f6a94f183f5ebcd2a2183f8bb SHA-1: 33e8b459f62f156f70b3b53e87923078bea8d035 SHA-256: e8baa325fabcc080d5caabc911fa470ed6e4f6d7906dc1b8a620998b2486f83a
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file flagged by multiple heuristics and ML classifiers as malicious, specifically identified as a phishing trojan by ClamAV. It contains a large number of embedded URLs, many pointing to disposable domains, suggesting a link farm or phishing lure. The presence of PDF_URI and PDF_SEO_DISPOSABLE_LINK_FARM heuristics indicates an attempt to direct users to external, potentially malicious, websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=sex+and+hollywood+black+veil+brides+lyrics
    • http://foxilajat.sportsontheweb.net/centrioles_structure_and_function.pdf
    • http://pojokup.getenjoyment.net/rujojafofebudodaw.pdf
    • http://vefijedos.22web.org/nuxexetanufuzupogo.pdf
    • http://garobunatuxovi.scienceontheweb.net/46076756974.pdf
    • http://citruss.space/husqvarna_chainsaw_manual_460xqbqd.pdf
    • http://medicinfo.online/fipodipejeregi7ngqp.pdf
    • http://suvuxivenorum.mypressonline.com/35828296539.pdf
    • http://xufamorazogubov.sportsontheweb.net/what_is_true_metrix_control_solution_used_for.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/d15fac6c-bcf9-4752-bd6a-b9953c365c72/zavidobofusupidik.pdf
    • https://s3.amazonaws.com/fajeloninesitel/serta_adjustable_bed_base_reviews.pdf
    • https://uploads.strikinglycdn.com/files/a93cab1b-1549-44ba-9465-3e17ba9814e8/how_to_study_for_ncct_medical_assistant.pdf
    • http://telusomabufa.onlinewebshop.net/72529139402.pdf
    • https://s3.amazonaws.com/sorogamat/87324608725.pdf
    • https://uploads.strikinglycdn.com/files/6a5a7c04-1610-4f3a-918a-13f5ba693d16/keurig_k145_cleaning.pdf
    • https://s3.amazonaws.com/lanorolowu/fur_elise_sheet_music_free.pdf
    • https://s3.amazonaws.com/wixanarer/graphic_design_courses_syllabus.pdf
    • http://puwagof.rf.gd/pofijuvokisimutivale.pdf
    • https://uploads.strikinglycdn.com/files/93eb0940-c05e-4cac-be63-a8d02e52de64/craftsman_lt1000_battery_walmart.pdf
    • http://derekom.rf.gd/25964210666.pdf
    • http://dezinolabebosod.atwebpages.com/latila.pdf
    • https://s3.amazonaws.com/wibadinavosunom/clearance_certificate.pdf
    • http://xujekapowizi.epizy.com/genetics_practice_1_basic_genetics_answer_key.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dd2f.bin
28c2ee57da3dcffd9232d206e58132b63174eeba82d76cd451e09f640c38ab38
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD2F 5656 bytes
font_01_sfnt_off0000f085.bin
07e6ee10218630e512034a24903aa330b3a957951e566d5543389c1d0f3fb17f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF085 10796 bytes