Malicious PDF — malware analysis report

Static analysis result for SHA-256 373197135d0fa140…

MALICIOUS

PDF

80.8 KB Created: 2021-04-03 18:18:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-20
MD5: bfb8cfbe94cae66137001eb15caf4134 SHA-1: 688dc04826dd62437bb41506b6c16c03c3676a09 SHA-256: 373197135d0fa1404524abbd3ecb3dc4d1539639e604b0aa565f469f9a5691d7
244 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many pointing to disposable hosting, and at least one known malicious redirector. This indicates a link farm designed to direct users to potentially harmful content. The ClamAV detection and ML classifier further support its malicious nature, classifying it as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/award?keyword=calcium+carbonate+in+soil+pdf In PDF document text
    • http://cabinetsop.xyz/688490183859g4k3.pdfIn PDF document text
    • http://brumbum2.xyz/410289112555c2c5.pdfIn PDF document text
    • http://zarudofafibitov.mywebcommunity.org/diferencia_entre_auditoria_administrativa_y_financiera.pdfIn PDF document text
    • http://fupefabesosada.mygamesonline.org/mudajarijewof.pdfIn PDF document text
    • http://getbuiss.online/3d_shapes_worksheet_grade_416ujr.pdfIn PDF document text
    • http://xovebud.mygamesonline.org/introduction_to_polarization_physics.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://a01f0313-f680-4530-87a9-ce77a10bb621.filesusr.com/ugd/ac0554_f955bcd9ff7c44208d4403f309682bfb.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/8747e086-61f1-483c-b7bb-17a3572be85b/jumanji_epic_run_mod_apk_1._4._0.pdfIn PDF document text
    • https://d128792e-e0a8-46e0-98ed-b941f5da69b2.filesusr.com/ugd/b98abb_43a39b68d4ad474a994b4636e5dff0f8.pdf?index=trueIn PDF document text
    • https://000bb656-a8cb-4e8b-9327-0b0ec99f56fe.filesusr.com/ugd/3f812e_d56ae1cf1b90430681ad6a4d94e870d9.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/526efa5f-ab29-4b9e-be46-a8e33f54d7c5/85693349645.pdfIn PDF document text
    • https://917ed8d3-8a9f-4c5c-a3ad-554e533308ad.filesusr.com/ugd/a4e402_0e08d01f825f41bebf641c17e13dbcc5.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/493762c1-004b-45a2-b5d4-a33e1f55b5fe/kofugopati.pdfIn PDF document text
    • https://b86313a8-447b-404d-ae6d-bc69740d899e.filesusr.com/ugd/e54fc7_1e86180811f84cb7a5dc5e21b51f5c69.pdf?index=trueIn PDF document text
    • https://bbaef297-c986-4b42-acb3-0fd65605e280.filesusr.com/ugd/e9fc71_fa2b969bdf2c410fb9bf6ab9d89a8bc3.pdf?index=trueIn PDF document text
    • https://b3a1a1c9-4f8f-4fb8-b7cc-7339030cc889.filesusr.com/ugd/162fe6_d0baedb08aea42dbb2ca1f694cf7309b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/7d0b724b-3ea6-48fd-93b1-441f00fad6e0/83106940093.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/defd5656-73f7-45e0-8e88-8523966b666a/ferrari_california_t_price_malaysia.pdfIn PDF document text
    • https://9e1e9198-0fe7-4103-8084-fdcc6befb8d5.filesusr.com/ugd/2f7815_3d05db11e1674e0a902e2b9c7df13923.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/9b9b9623-e5ac-45af-bb90-73a1ef289a4b/pufawobus.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4d155a47-1ae4-4613-9c9e-055ad098b073/craftsman_4200_watt_generator_run_time.pdfIn PDF document text
    • http://kuxemozoxabonag.onlinewebshop.net/social_learning_theory_examples_in_movies.pdfIn PDF document text
    • http://vidoniwofunevan.onlinewebshop.net/majubewusokiwit.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/789ca101-ea2c-4e1e-a236-9bd1faf6315b/how_to_draw_faces_for_beginners_easy.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8a2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE8A2 5344 bytes
SHA-256: ae38ae40b0b61338995fdef3fd5ce4cec7fbda0cc7b641ad2779d5ae85ec0b5d
font_01_sfnt_off0000faad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFAAD 10592 bytes
SHA-256: 5362fb443b83da2832fd1a939ed86de8303d13c3d848cb080940e451be8b6403
font_02_sfnt_off00011f31.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11F31 16060 bytes
SHA-256: d1a84ba8f0e4a827a048d387db8dd5dae3538f1c7e72415b16af587a9947cdc7