Malicious PDF — malware analysis report

Static analysis result for SHA-256 f78db138a9a8cd49…

MALICIOUS

PDF

91.9 KB Created: 2021-05-16 05:22:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 4f4c1fe78d596332a9bc5b549b709175 SHA-1: 2f87c3c1e431a6c7c3f856709bcc1f2848a8456c SHA-256: f78db138a9a8cd49fb2f39eff1adb998beeda219bcd7063ad9bee047be1f5bd9
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous embedded URLs, many of which point to disposable domains or link farms, indicating a phishing or malware distribution attempt. The ML classifier strongly flagged this PDF as malicious. While no scripts were directly extracted, the presence of many external URIs suggests the document is designed to redirect users to malicious sites, likely for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 4

  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/strik?utm_term=sub+zero+refrigerator+532+service+manual PDF link annotation
    • https://cdn.sqhk.co/bojodunaluko/gPhSgcn/nudives.pdfIn PDF document text
    • http://smotrikino.fun/will_there_be_more_miss_peregrine_movieso6my8.pdfIn PDF document text
    • http://tugrull.com/walgreens_automatic_arm_blood_pressure_monitor_instructions9brek.pdfIn PDF document text
    • http://kopogaxepaku.sportsontheweb.net/60142113379.pdfIn PDF document text
    • http://fosonelotila.medianewsonline.com/32579095457.pdfIn PDF document text
    • http://xawamiwupajev.mygamesonline.org/mibetelidonugurebepevuz.pdfIn PDF document text
    • https://cdn.sqhk.co/lupobikud/i5hdZUu/zixab.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412591/normal_6042d8660855e.pdfIn PDF document text
    • https://cdn.sqhk.co/mopomotop/cjhC7Bd/no_app_drawer_nova_launcher.pdfIn PDF document text
    • http://nebemor.mywebcommunity.org/94282134838.pdfIn PDF document text
    • http://fuzubijixulux.mygamesonline.org/how_to_solve_ratio_as_a_fraction_in_simplest_form.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4410694/normal_60541d0c0c332.pdfIn PDF document text
    • http://korefubelexusiz.medianewsonline.com/cassava_brown_leaf_spot.pdfIn PDF document text
    • https://cdn.sqhk.co/rizitewav/Ugghfhj/lyrical_dance_songs_for_young_dancers.pdfIn PDF document text
    • https://cdn.sqhk.co/zoxowowi/iTihgHU/tekutoromekogomimuluvimu.pdfIn PDF document text
    • http://jedomagisuw.getenjoyment.net/ap_budget_2020_20_download.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417220/normal_606810e08998b.pdfIn PDF document text
    • http://hurleyshamburgers.com/calendario_2020_por_mes_para_imprimir_gratis76c1n.pdfIn PDF document text
    • http://zuzorovix.scienceontheweb.net/31520038178.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://dipuleragix.onlinewebshop.net/tupodomafikevuzubutesujuv.pdfIn PDF document text
    • https://7e073981-ad1c-4081-8dc0-76946ba36063.filesusr.com/ugd/c4f63d_ab60816ec063442eb954888b472c86fb.pdf?index=trueIn PDF document text
    • http://tipokeviti.atwebpages.com/10995294570.pdfIn PDF document text
    • https://94226b1b-8363-4ad6-a779-e61b7b16ff5b.filesusr.com/ugd/b3bc21_414bcd75e14e43bdb65ae8f389eeb8ad.pdf?index=trueIn PDF document text
    • https://5a2ada08-5b6c-402a-b0df-3636415b461e.filesusr.com/ugd/434ae6_b1ebf7a235f044e6b273d8df342b90e7.pdf?index=trueIn PDF document text
    • https://ee67c5b3-b4d3-4257-b425-af55881d3a68.filesusr.com/ugd/c60da7_2278c2657b264e3484cd7e3f4403a33d.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ff9f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF9F 5856 bytes
SHA-256: ad8a670ea55407a4fef4c245f0bfb6873a582b052c583ceec6abed035ce7fc9c
font_01_sfnt_off00011384.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11384 11904 bytes
SHA-256: 15af0b4ba506d785d3f3ff74f67128bea42a07a4d2807c92fa36df0a9de6e306
font_02_sfnt_off00013c43.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13C43 16204 bytes
SHA-256: 532315dfdc59b350d447ad91845dd8cc72a836e684f536ab9a4305dc5b53fb8e
font_03_sfnt_off00015173.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15173 4324 bytes
SHA-256: cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34