Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d1005ff584acfec…

MALICIOUS

PDF

92.5 KB Created: 2021-03-08 21:21:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-26
MD5: d7090469644339111014b484d11844ee SHA-1: 5fb45fe4d5ea99e38c1d65b4633b6ddf0607fe80 SHA-256: 1d1005ff584acfecc491ed7c204662eea24c2daaa471653272b9b8c101af09a1
244 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, with one specifically identified as a malicious redirector pointing to 'dafemum.ru'. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' and the ClamAV detection 'Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0' strongly indicate malicious intent. The document body, though heavily obfuscated, contains text that appears to be a lure for a 'sociology textbook', suggesting a phishing or malware distribution campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/award?keyword=pearson+sociology+textbook+pdf In PDF document text
    • http://walolexokesufa.sportsontheweb.net/simple_java_game_code_example.pdfIn PDF document text
    • http://nokasosozigof.mypressonline.com/what_is_dw1_transmission_fluid.pdfIn PDF document text
    • http://dadivasim.sportsontheweb.net/talinevetelibimeven.pdfIn PDF document text
    • https://cdn.sqhk.co/sufokorume/o5jgjif/bottle_flip_3d_hack_apk_download.pdfIn PDF document text
    • https://cdn.sqhk.co/rijomawonuj/ccUNwgf/84123638323.pdfIn PDF document text
    • https://cdn.sqhk.co/mugapowejog/eknjaHs/prince_harry_net_worth_2019.pdfIn PDF document text
    • https://cdn.sqhk.co/zaxuloxedu/9YaZoRK/tanglefree_panel_blind.pdfIn PDF document text
    • https://cdn.sqhk.co/tefozakozup/fzPdGcU/26506597629.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://0fc0baf9-b884-4fcd-968e-f93c0f938930.filesusr.com/ugd/68ec51_44df2271daf54fde85086dc3e0421945.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/f63f9e2f-57af-44fc-a3e6-14c58d5b24a9/every_young_mans_battle_age_range.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa50fb2f-68c7-47c1-b77f-195b47fe04e6/miledebojibif.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/91fc6f76-8fab-44da-87e9-ee206ee7228d/49760896450.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5e14afed-0f54-4f96-9af4-af1073abca5d/how_to_make_a_hard_return_in_excel.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/005780ea-5cfc-4313-b03c-8e930f1d21f1/orbit_sprinkler_timer_manual_operation.pdfIn PDF document text
    • https://746420f6-3007-491b-ba72-fd43be5094e5.filesusr.com/ugd/277b62_9a4cacef30104303854c9b64ff3ea92b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/2e16e363-8eb6-46cd-90f9-beb8b916e777/bebumukewasakopew.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7b7dffe9-af41-42ae-9c1e-4e9497c48e56/30293182882.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4d37e72b-11a4-4292-96b8-ae9f26010712/dyson_dc25_animal_reset_switch.pdfIn PDF document text
    • https://ce55c564-0e79-48ac-bd91-a034cff8554b.filesusr.com/ugd/bd1fc0_f61e2f916cf1497e9530719fa8e49dcd.pdf?index=trueIn PDF document text
    • https://d6d3a1c5-32ce-46e9-ae92-c5b8d84d65d9.filesusr.com/ugd/a3b54b_bcb38244ca4748ec9937f56b78d00c99.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/68b3e8a9-e54b-43ea-9019-d85dc51728f7/why_9_days_of_prayer_for_the_dead.pdfIn PDF document text
    • https://b01ec662-dec5-4f54-b977-8708717d6054.filesusr.com/ugd/07e02c_e569057a192f4e9d9571a3b2e9fb3e7b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/86b028e8-0156-4638-901b-c828fa017b55/how_to_program_new_directv_remote_to_box.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000128f6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x128F6 5696 bytes
SHA-256: b2dc9e6a7903115da058f56e1fa4a8d9d9953e83988deaa320399c49ec4f1333
font_01_sfnt_off00013c71.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13C71 11360 bytes
SHA-256: 1fd9a945de2f7655b83cde19b5131a805273000246a0328b1653c55b9b2496d9