Malicious PDF — malware analysis report

Static analysis result for SHA-256 35fdc12b71f75fb1…

MALICIOUS

PDF

76.0 KB Created: 2021-05-15 10:40:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-20
MD5: 181fc7a4d63b28191828cb02fb143b77 SHA-1: 237db4185f911bc7d617376cfcaab2be92088fee SHA-256: 35fdc12b71f75fb1c58562a4dce44f0a97efd29458515ccabfc80310370ce8a4
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a large number of external links, many hosted on disposable domains, suggesting a link farm designed to direct users to potentially malicious content. The document body is heavily obfuscated and appears to be generated content, further supporting a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/strik?utm_term=how+to+find+piriformis+trigger+point PDF link annotation
    • http://sunepoxuvigos.66ghz.com/49472351166.pdfIn PDF document text
    • http://sagokorize.22web.org/98040704702.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365627/normal_6038f96bb3962.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417998/normal_602ca1ba00c40.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4381546/normal_6058e31266340.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4426945/normal_6023eb966d792.pdfIn PDF document text
    • http://salearea.pro/toxifelaf7hk0i.pdfIn PDF document text
    • http://meblik.su/telecaster_guitar_plansbw7tn.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://lojuwuwa.rf.gd/kowisovunibodukejiritufev.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d850d88a-fa61-4c86-86b1-a6fb8eba34f0/what_is_stock_market_technical_analysis.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/db7077dd-6e3e-4a28-86ff-ace9a0d63f39/oracle_12c_installation_on_linux.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cc0d0dd9-d914-41b8-b96f-b312309f896b/rifenokuvuzalutulud.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/52329ded-63a0-438a-ae58-5faffb84a425/31215148711.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d6981ebe-718c-4223-b103-81997eae414c/is_famous_daves_cornbread_sweet.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f9dae94a-0a42-474d-83ff-8fa9a413d537/57744028608.pdfIn PDF document text
    • https://6478d21b-237c-41b5-add8-96d7b9819624.filesusr.com/ugd/c7ef1a_2789232895814e2c8aa6b84acff1875c.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/a759ca99-11a0-472f-b3f7-45c72df85e98/zarozujitunajun.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f7603c76-c503-4d34-98d8-e74b744bc38d/10586962631.pdfIn PDF document text
    • https://217ba8a6-026c-4a9e-b1ce-2eadff0a4a08.filesusr.com/ugd/3d7af5_37e429a5c31146efa455d42833b402bc.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/2b2a1a6b-3b69-4b6f-bebf-cf9278ee85ed/simplicity_lawn_tractor_steering_problems.pdfIn PDF document text
    • https://9c43cb74-45e3-47de-9527-fda2e8336169.filesusr.com/ugd/af0aa9_0d68aab5858b42628e74fecfa40a618a.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/61c1caef-19c6-4170-abb0-631dd3bbf346/iron_mike_pitching_machine_balls.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec7f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC7F 5172 bytes
SHA-256: c8c5949934e09c64e9ae8f5fc4b0f473c68c4cfa4dc5186df94fce5f4ecf85ad
font_01_sfnt_off0000fe1d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFE1D 10712 bytes
SHA-256: bc7801aaceee17d25e6c0bedbb4c377e0bc7eb87c0e09905b98daf411fd9824f