Malicious PDF — malware analysis report

Static analysis result for SHA-256 5185b2e33c88cfd5…

MALICIOUS

PDF

120.8 KB Created: 2021-02-08 07:59:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-12
MD5: 50d735a6762ffe63129a62c3730be2ee SHA-1: 048853336a856a2b0541f1052e5cfd27dd7f40b7 SHA-256: 5185b2e33c88cfd5422f85eb877d24cb2b8ff235db15307f60d8c369adf74511
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection and an ML classifier indicating maliciousness. It contains numerous embedded URLs, with at least two pointing to potentially malicious domains ('jottigo.ru' and 'zinusefubowewet.22web.org'). The 'PDF_SEO_DISPOSABLE_LINK_FARM' heuristic suggests the document is designed to host many links on disposable domains, likely for phishing or malware distribution. No scripts were extracted, but the presence of external URIs and the link farm nature of the document indicate an attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9834

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/123?utm_term=moi+gov+aq PDF link annotation
    • http://zinusefubowewet.22web.org/36363809872.pdfIn PDF document text
    • http://netewe9.xyz/25493565230mfdwa.pdfIn PDF document text
    • http://graatorama.fun/13759465549yings.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4498366/normal_5fe401f342585.pdfIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • http://bejiteviv.epizy.com/intermediary_guidelines_it_act.pdfIn PDF document text
    • http://ruxuvejefo.epizy.com/spring_framework_free.pdfIn PDF document text
    • http://xamipekuxedatif.rf.gd/duripajovogisale.pdfIn PDF document text
    • http://dilexaluv.epizy.com/dead_island_2_android_apk.pdfIn PDF document text
    • http://gumupomomoripu.rf.gd/dazexilalusunebuxozisu.pdfIn PDF document text
    • http://kenozajawatulaw.rf.gd/three_phase_auto_transformer_diagram.pdfIn PDF document text
    • http://girigiroret.rf.gd/anzaldua_borderlands_full_text.pdfIn PDF document text
    • https://s3.amazonaws.com/nedijowewoded/kylie_hutchinson_innovative_evaluation_reporting.pdfIn PDF document text
    • http://xolazituvote.epizy.com/97013712246.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text

Extracted artifacts 11

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off00013f29.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x13F29 6944 bytes
SHA-256: 2b70063f637f683c4b1dbad419f76f9e6585bcc4e166a781d4dc1ab67589d42f
stream_012_off000191c0.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x191C0 24676 bytes
SHA-256: f0d9936957f6790b717947ced26098234472e2405d43d181b018a4cf03d78731
font_00_sfnt_off0000dc74.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC74 3664 bytes
SHA-256: baa9aa3a98b39f7d3e1299c671964e4b6660db5cd5e82101efcff171ab2cddf7
font_01_sfnt_off0000e9c5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE9C5 4740 bytes
SHA-256: 44fb81b7c2a7c378d8e572c9920fd3749195a46443fbdf74bfd910b13b528ebc
font_02_sfnt_off0000fa0c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFA0C 5960 bytes
SHA-256: fe4318c3d9c44970d7a15a04f9687394dcccbee3b72e570517952353decc07ed
font_03_sfnt_off00010d7b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10D7B 5088 bytes
SHA-256: 7a0b1a8373d352b860f25a711a6e0d9e4581e8996573f8016ebe757e19f6d6a7
font_04_sfnt_off00011f78.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11F78 4892 bytes
SHA-256: cbf2ba086696b78de1e86917ce85bcdbbd5612915abc93da754b110db6c3fe12
font_05_sfnt_off00013074.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13074 3964 bytes
SHA-256: 30b5416339101fc0fdca2e09169d2cf58bef530dec424e742550adfe42544094
font_07_sfnt_off000151c1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x151C1 4984 bytes
SHA-256: 1a5bb8b04b37a2540a1c58fb4772cbf43000ef1f2f530109dab0931b40b75469
font_08_sfnt_off000161ae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x161AE 15128 bytes
SHA-256: 7d928bc6fed16c84adf97668c1a0be5f4c3236549250a4e7abc83fad1bdf8630
font_10_sfnt_off0001bfd5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1BFD5 5392 bytes
SHA-256: 43077eee7226c4827c89ccded79b4708e03d30ca290e06490adb9b37738cd3c0