Malicious PDF — malware analysis report

Static analysis result for SHA-256 0050249622976294…

MALICIOUS

PDF

87.2 KB Created: 2021-03-20 17:21:39 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-22
MD5: 87118d902f9eb5cc5188a9d2980a527f SHA-1: 20c18fe3f6e98e45d195615c1b8fda82ccf9d61f SHA-256: 00502496229762944d35b93a73acbdec5f1917638e2fb07feedb374bac0bfadf
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many hosted on disposable domains, suggesting a link farm designed to direct users to malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or a scam. No scripts were extracted, but the PDF structure itself is used to facilitate the malicious redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/award?keyword=the+beatles+songs+lyrics+pdf PDF link annotation
    • https://fanamavikere.weebly.com/uploads/1/3/4/6/134610997/valabubupujuges-didomulix.pdfIn PDF document text
    • https://xerotopofuwega.weebly.com/uploads/1/3/1/4/131406930/8294194.pdfIn PDF document text
    • http://xofebuledat.scienceontheweb.net/cuisinart_coffee_maker_dcc_1200_troubleshooting.pdfIn PDF document text
    • https://xizuxikeg.weebly.com/uploads/1/3/0/7/130740292/gazijobabi-golegeraz-panibu-rujixagagom.pdfIn PDF document text
    • http://xijonofupawulo.mypressonline.com/38872117457.pdfIn PDF document text
    • https://mosiwiwemupal.weebly.com/uploads/1/3/1/3/131383889/bibokofoweg_sugoxavuta_kerukogov_vabozibipubujij.pdfIn PDF document text
    • https://wilulesutazi.weebly.com/uploads/1/3/3/9/133997377/jikedibigulu-jufofaxoname.pdfIn PDF document text
    • https://fezugewibopav.weebly.com/uploads/1/3/5/3/135346468/dimima-xulaboteselele.pdfIn PDF document text
    • http://xibiselid.medianewsonline.com/what_are_the_three_different_types_of_audiences_rhetoricians_look_at.pdfIn PDF document text
    • https://jukusixod.weebly.com/uploads/1/3/1/4/131483076/1026140.pdfIn PDF document text
    • http://gomesuzos.mypressonline.com/math_formula_class_12_download.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://6c473ef0-402e-45f0-9f95-6bc7e89a6a1a.filesusr.com/ugd/5518c3_9447fb5d11514e399ff66887595117f8.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/bb8435dd-c5ba-41f5-93bb-2d8c08726485/dogolaxapipogij.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/abbac075-df0c-4d3b-9e51-cfbf6edfe42f/how_to_check_4_wire_oxygen_sensor.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e5f4a7c5-a942-47c9-bdb1-99fdc7e1a707/what_is_the_box_model_mcq.pdfIn PDF document text
    • https://107a3552-ed21-4f5d-95e3-510b6eae4444.filesusr.com/ugd/21bbef_750e79e4eafe49f6804dae909d4e9b47.pdf?index=trueIn PDF document text
    • https://57eba762-b826-4879-8d7a-7f480aba2934.filesusr.com/ugd/e89c2b_0058307220624b8481da4c0042cf62d3.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/20007f0c-fb77-49de-a0d6-d2a93c936816/xeturiratumiro.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dc34346f-7d15-4c35-8b16-b6d750b24fae/how_to_pair_soundpeats.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e4fcaaaa-832a-4b37-8b58-7587bafa90db/how_to_reset_yamaha_receiver_rx-v383.pdfIn PDF document text
    • https://b67fa923-03b4-4d21-b555-95ff628d7525.filesusr.com/ugd/1d4b90_c88a2885487a4a04b44f89521f89fb8a.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/8ae66b08-f813-41b0-877f-20f4f8bd233e/total_gym_pro_workout_routine.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/99c64a26-a57e-4c02-92c0-00f2312273e4/sony_xplod_car_stereo_bluetooth_connection.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011631.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11631 5608 bytes
SHA-256: f54b76007ac8be7d823f226229ab8b65a615d17e3014ef54f39f81b6b7216570
font_01_sfnt_off0001293d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1293D 10660 bytes
SHA-256: 071e68b15353c45fb8dc127856693b493f00929c9953d05980e6958461554271