Malicious PDF — malware analysis report

Static analysis result for SHA-256 3444a36ff7a2f33d…

MALICIOUS

PDF

125.1 KB Created: 2021-04-19 18:46:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-02
MD5: 3400bc7231bcec773da576d21a1adebf SHA-1: 4ee0e07959e0389bb6ed06923dffc21447fd8bdd SHA-256: 3444a36ff7a2f33db6f1af5357ee4dc5377f08fc98f187331f5fb71ebd4089be
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many pointing to disposable domains, suggesting a link farm or SEO spam operation. The ClamAV detection and ML classifier indicate malicious intent, likely phishing or malware distribution. The embedded URL and the document body's deceptive title "What is binomial theorem in hindi" are used to trick users into visiting malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9403

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/strik?utm_term=what+is+binomial+theorem+in+hindi PDF link annotation
    • http://hairsprof.ru/at_what_age_can_a_person_receive_social_security_benefitssg9ov.pdfIn PDF document text
    • http://hightrade.club/romeo_and_juliet_law_comzpsqe.pdfIn PDF document text
    • http://digitaltoolsfor.xyz/turalojolumawebukokuwde795.pdfIn PDF document text
    • http://card2card-perevod24.site/gardners_art_through_the_ages_the_western_perspective_14th_editionrsgv1.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4414498/normal_5fcd303fd2986.pdfIn PDF document text
    • http://stepka2016.xyz/erb_palsyzpp0b.pdfIn PDF document text
    • http://presalle.xyz/bose_acoustimass_10_series_4_review93arz.pdfIn PDF document text
    • http://samozanyat.info/sepuzexomanogeni6u9p9.pdfIn PDF document text
    • http://premial.su/84520154655mxutq.pdfIn PDF document text
    • http://1xbets-regs.site/945504823170f8md.pdfIn PDF document text
    • http://relax35.ru/vemawipefukoxisubipelono1uz.pdfIn PDF document text
    • http://bcpzonasegur4viabcp.com/65208407520l89lh.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408595/normal_5fdc4146e1a1e.pdfIn PDF document text
    • http://freud.icu/442808430271wjmi.pdfIn PDF document text
    • http://damvglaz2.xyz/how_to_use_a_kidde_lock_box7snsh.pdfIn PDF document text
    • http://cabinetshub.xyz/nikidexexa2qn52.pdfIn PDF document text
    • http://idealica-italiaofficial.site/56580908310y7ue1.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4418166/normal_5ff3a49f25586.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • https://09972071-4174-499b-90b1-de3619f59f53.filesusr.com/ugd/d1c05f_21e792f335734948b91e7f8a7a712636.pdf?index=trueIn PDF document text
    • https://96a9e3af-f0c3-4048-9e6c-0ad8da3c6018.filesusr.com/ugd/15d534_748b3ad1ca74415e999f340207d905f4.pdf?index=trueIn PDF document text
    • https://49432a94-54bc-4d13-9d12-ea41d731e1b8.filesusr.com/ugd/a7c689_4384e4392a084541b817b83e3c775f51.pdf?index=trueIn PDF document text
    • https://0df6220b-9630-4647-aab6-0d9db69b9d59.filesusr.com/ugd/8b97dd_7a677ccb489944908554d1b62fa3fcd2.pdf?index=trueIn PDF document text
    • https://d872ce2a-2baf-4032-ab86-ab75b2f66d52.filesusr.com/ugd/338562_b24b356e5dbf4e0c98b29794d74d4cde.pdf?index=trueIn PDF document text
    • https://98be45bc-63b9-4117-aff7-84a3d4f2c4a0.filesusr.com/ugd/90c678_22c5396c8d494a6bbcd79fd2ec3e79be.pdf?index=trueIn PDF document text
    • https://61090d85-22e6-4724-b969-52a17785150c.filesusr.com/ugd/952c2e_e4e199d8d4d14866a32dc509a9f300c6.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_013_off0001a1c3.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1A1C3 18756 bytes
SHA-256: 2bc6b2d83e0437956eccf3d3e562bf814723c9f8e45b5d104bcd41b96f2fc09b
font_00_sfnt_off0000dfa0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDFA0 5684 bytes
SHA-256: 721cc2fdd3dc595dcb3ceb283710897e6e3f946895107a6db3eba0a731c1121f
font_01_sfnt_off0000f37d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF37D 5220 bytes
SHA-256: 47f6292d744e76b5d0f36dd9ac33c4656fb5409147b9d4cbe82ece9e72d3273f
font_02_sfnt_off00010511.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10511 4668 bytes
SHA-256: f509227135cbc3ed65efde478a480c928b54b81adfacc197aba5e07e0fbca56c
font_03_sfnt_off000114b5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x114B5 6040 bytes
SHA-256: 623f3dc160466080235b5d69e2cc70c9e2e99ef737c273ede0d3d2ca18f3e99e
font_04_sfnt_off0001283c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1283C 3048 bytes
SHA-256: b5c6b6e0c9ada0bf1c6b02372d38a6194b0fc304f51b15768a03b7bd417def48
font_05_sfnt_off0001344b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1344B 2328 bytes
SHA-256: 18b250f24057ce91e4a59b25c1eec79fa8b4d7e2cb9f6c0de02c7e032a072fd4
font_06_sfnt_off00013f00.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13F00 2108 bytes
SHA-256: 5fc9e2cd4e7ad04544edda2023dd698132b65daf167a61e09de9fd8de66d8b52
font_07_sfnt_off000148d6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x148D6 2604 bytes
SHA-256: 5fd53e2058c4f5d98b70161d670f1e42036942552fef68ac845a5e47e2d7f715
font_08_sfnt_off000153f4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x153F4 6640 bytes
SHA-256: 593a452f0795506ac97007ad32b21767cc543cb1bc716fd74108abb5279d52e6
font_09_sfnt_off0001659a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1659A 4336 bytes
SHA-256: 87016e8933cc862d1d188edfbee698abcff8178ed3d6b510b61737ee02f60284
font_10_sfnt_off00017345.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17345 15168 bytes
SHA-256: 28d8711155f882b7070fd00a9dd012bd2826ba212f8eb6c8480fbe3d066a892d
font_12_sfnt_off0001c05f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C05F 6076 bytes
SHA-256: 8d791558f58063214e942ec1fe211e42f77adc5d4a18e4ca150cae0307f1a836
font_13_sfnt_off0001d5cc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D5CC 2608 bytes
SHA-256: 89aa5ef39ecd647c310fa7d43209dd0d208a608e38381102f2e40635d4f29b56