Malicious PDF — malware analysis report

Static analysis result for SHA-256 ece168a6ce048f82…

MALICIOUS

PDF

82.4 KB Created: 2021-03-13 16:57:48 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-25
MD5: 86c6670ba2b5ac251314855635ce8777 SHA-1: 28321071317f6e109c62e4cd7a2efe1a6b94847e SHA-256: ece168a6ce048f8291364c39e22d242a290f6da03db8b3f2219751f6c99efd84
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. It contains an embedded URL that redirects to a phishing site, likely intended to lure users into providing credentials or downloading further malware. The heuristic 'PDF_SEO_UTM_REDIRECTOR_LINK' specifically indicates an image lure for free-download phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=google+docs+beetlejuice+movie PDF link annotation
    • https://cdn.sqhk.co/mifigatira/giagihi/27636527809.pdfIn PDF document text
    • http://leafester.online/60846148924k3hcz.pdfIn PDF document text
    • https://cdn.sqhk.co/xanapaje/ctaOJ5B/ristar_classic_apk_mod.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413713/normal_5fd3cfffc62f3.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4410956/normal_5ff9efba710dd.pdfIn PDF document text
    • https://cdn.sqhk.co/nokotadi/6ihmhK3/easy_21st_birthday_cake_decorating_ideas.pdfIn PDF document text
    • https://cdn.sqhk.co/mugegiduveb/ccCichc/91318548030.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4454694/normal_5feedb6be0402.pdfIn PDF document text
    • http://svoytrylend.xyz/767506078353ooot.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4501360/normal_603ceb3eca4aa.pdfIn PDF document text
    • https://cdn.sqhk.co/nivavepe/gchhrxv/list_of_calories_in_food_items.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/26c1c59b-e990-485b-9df5-083727e419d2/mitologia_griega_dioses_semidioses_y_heroes.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c8dbd542-b4e9-4f52-aaab-d5ee798ebaa9/vuwogexupen.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9c318bbc-c84e-4ca8-9893-4a3ee050d62f/42563785771.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f3689f75-0413-42fb-b1ec-602502dc5c8b/the_great_mental_models_book_review.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/75757655-95e1-43b0-9ce9-c29d05645cb7/68249488392.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2f456442-3078-4aa9-94c7-a1ffe0c2e48a/kesexojenoxigep.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/38bc1e52-d9e0-42e8-b00f-8b65dde08eee/navy_e5_advancement_exam_results.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/95f3c2ce-1bc3-4100-a0fb-2b010be2333a/beckers_world_of_the_cell_7th_edition_free_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e6571695-63f9-4a3f-96da-a3a1379b3504/charlie_and_the_chocolate_factory_original_broadway_cast_recording.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dcec1884-183b-49c2-ac3c-fd311384c04a/news_report_examples_for_students.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1232b9d3-4106-46cb-8499-7014f1a9b3f3/hp_laserjet_p1102w_setup_without_cd.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ab8b0ada-21ea-45d3-9644-282ef2a7f36a/html_css_class_attribute.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/99c7b555-37c0-4e5c-b3da-087309d6d3a0/pizin.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000efa8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEFA8 5260 bytes
SHA-256: 88ddd4735861e9e670b6b857775525ad852714dee04498f7b86862529b03124a
font_01_sfnt_off00010193.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10193 10556 bytes
SHA-256: 810938452a72fec04ed7a4e7c883d5340897a665240064a7d82855c48a3e08d4
font_02_sfnt_off00012601.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12601 16388 bytes
SHA-256: 0c82561ead172ac0e51412abe629b5944d5f81f469066018c017fef234fe4ba7