Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea3302c5bd5aa74c…

MALICIOUS

PDF

136.9 KB Created: 2021-05-03 06:28:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 3742f01f0b0b84640cc0c54d2bf7248b SHA-1: ee25566e92e516477b2f9694f36283e4bb6b47da SHA-256: ea3302c5bd5aa74c0587064007ff01c8f42c3b32fa834e608c0ab5317918b882
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, with one prominent URL pointing to 'dugedepap.ru' and containing a 'bose 901 for sale' query parameter, suggesting a lure for a phishing or scam campaign. Heuristics indicate the PDF is a link farm on disposable hosting, and ML classifiers and ClamAV strongly flag it as malicious, specifically as a phishing trojan. Although no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9987

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/strik?utm_term=bose+901+for+sale PDF link annotation
    • http://salearea.pro/no_oyes_ladrar_los_perros_analisis_literariot1pfl.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4527237/normal_5fdadbecac2f2.pdfIn PDF document text
    • http://zedakobogesa.mypressonline.com/careless_whisper_partitura_sax_tenor.pdfIn PDF document text
    • http://newberginvestmentproperty.com/barejutatejozi8agmz.pdfIn PDF document text
    • http://good-production17.site/4468916868hfkz2.pdfIn PDF document text
    • http://aycotoro5.xyz/bewizolakiweweras6ct.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4378606/normal_604715c0546c0.pdfIn PDF document text
    • http://pubofumoxo.scienceontheweb.net/section_185_of_companies_act_2020_amendment_2020.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4421039/normal_6054904566cd4.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4453720/normal_5fcacaab94a33.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4383689/normal_60559db095ca2.pdfIn PDF document text
    • http://kogowetek.getenjoyment.net/fish_farming_business_plan_in_india.pdfIn PDF document text
    • http://gajonedorebuko.mywebcommunity.org/89346320109.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/ab98ebd0-b745-42fc-b302-395092cfc856/kijotutepiriwevebe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6d666271-783e-4453-a373-b4ec2992516c/7111134927.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a3f002a4-5ad6-49a1-b1c6-ddbf1772b16d/fusidolixezun.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/517b7c33-f387-4783-b295-7d5e6a835fe0/lazupisiluz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7bc31af3-4723-406a-8ff0-0c0d5b23fdf7/business_mathematics_college_course.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2f607241-0201-4442-9e86-375920959254/line_6_pod_go_review_musicradar.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/300a5901-cc6c-4d0d-a5fc-aaef2615b906/kuretarig.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a50755c9-7fbb-4dd2-b8dd-5ff79b2bac54/air_hogs_helicopter_charging_instructions.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fd5a78a3-4ebb-4d4a-a873-d2a154405df9/rojuwatesadotelawatosudur.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/303bf1fe-fe65-4eb3-bfdd-5db816df2fac/seminario_filosofia_del_derecho_unam.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001cf91.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1CF91 2888 bytes
SHA-256: c5e3a892f7200b844efed0c299c7f3c82e10a8bdf1bc782c11df912ce6200ca9
font_01_sfnt_off0001d9db.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D9DB 5160 bytes
SHA-256: c1538ed6007f31b7019c2b65328a3372ef8e2b8d9eb8648dcdbb4b20606b7551
font_02_sfnt_off0001eb7d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1EB7D 12568 bytes
SHA-256: 1cc9bbb29409a3b0a09d2128dfb5e6ac1cc588ec2c4542e38f2742be5f781b47