Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed95136e8d0f4ff3…

MALICIOUS

PDF

82.0 KB Created: 2021-09-21 07:03:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2021-10-26
MD5: c94f1f50dbabcc1c35b492ba23c4b3d1 SHA-1: f8379e2a0d72dfab06fc8266e95e0c1038751e30 SHA-256: ed95136e8d0f4ff3587fa530cb18b5a8983919dfba85f014a4f9365cc15cbbf1
134 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains numerous external links, many of which are on disposable hosting, and includes a deceptive 'download' button. The presence of external URIs suggests an attempt to redirect the user to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://infrive.ru/uplcv?utm_term=need+for+speed+hacked+apk PDF link annotation
    • http://florylaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/3162329023.pdfIn PDF document text
    • https://perfecthospital.org/FCKeditor/file/detatepomexop.pdfIn PDF document text
    • https://calmoinc.com/upload/editor/file/bedarifob.pdfIn PDF document text
    • http://hattingtoemrerogsnedker.dk/userfiles/file/nijaxitaroj.pdfIn PDF document text
    • http://alfavit.tv/userfiles/file/40427967468.pdfIn PDF document text
    • https://limsurempat.com/contents/files/sorebazilatasekodila.pdfIn PDF document text
    • https://aarhuskortet.dk/images/file/dupomuxe.pdfIn PDF document text
    • http://cephedanismani.com/images/pages/file/voxerujovo.pdfIn PDF document text
    • http://www.colormotion.cz/UserFiles/file/12111355018.pdfIn PDF document text
    • http://meijialx.com/ckfinder/userfiles/files/xikixurazanine.pdfIn PDF document text
    • https://www.chablis-gautherin.com/ckfinder/userfiles/files/69968257986.pdfIn PDF document text
    • http://spartaksedlec.cz/spartaksedlec/userfiles/file/61134924317.pdfIn PDF document text
    • https://cokhivietuc.com/img-vietuc/files/natofazowiwebiwepip.pdfIn PDF document text
    • https://callhfelectric.com/wp-content/plugins/formcraft/file-upload/server/content/files/16133880d72e19---93166936263.pdfIn PDF document text
    • http://synergyproperty.com/images/files/jadufeliketixovobewari.pdfIn PDF document text
    • http://missteenqueenuk.com/userfiles/file/xubero.pdfIn PDF document text
    • http://www.its-dph.cz/admin/fckeditor/editor/userfiles/file/bifulupemadurewujonorire.pdfIn PDF document text
    • https://bhopalliteraturefestival.com/mpsdp/uploads/files/1285934987.pdfIn PDF document text
    • https://millvalley.com/wysiwygfiles/file/nutif.pdfIn PDF document text
    • http://kyanite.tv/userfiles/file/51074713196.pdfIn PDF document text
    • http://jiachuankeji.com/upload_fck/file/2021-9-12/20210912083032300819.pdfIn PDF document text
    • https://vcubusinesssolutions.com/userfiles/file/bubowesulir.pdfIn PDF document text
    • https://pvesc.vn/uploaded/file/nifokafewimopigotesurikom.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c1c4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC1C4 16792 bytes
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
font_01_sfnt_off0000d9db.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD9DB 10448 bytes
SHA-256: 6b6210393cb650abf160d404593eea707c0a3390ee813bf2dfc595b40e385b6d
font_02_sfnt_off0000f1b4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF1B4 19800 bytes
SHA-256: 74de33aab8dc60485255080e0bc3611c19089ed0f54e0f2b7b7e1a50b79debf2
font_03_sfnt_off0001248f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1248F 16152 bytes
SHA-256: 0f62411f33c11177563efe33ebd0105f37df2a55e6a92cd5aec3f2cc21bf3838