Malicious PDF — malware analysis report

Static analysis result for SHA-256 58dba224cf24efe9…

MALICIOUS

PDF

74.5 KB Created: 2021-04-16 14:24:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 19c50f20cf1be730335afca9cabfc883 SHA-1: 583137efb24a48afaa162f1ea853b62f837a0084 SHA-256: 58dba224cf24efe9d356ae50f4fb805306d0d08b89f38ce8f3ce953c7b828abf
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which are hosted on disposable domains, indicating a link farm or SEO poisoning tactic. The primary URL, 'https://zajinet.ru/strik?utm_term=navy+reserve+advancement+results+2020', suggests a lure to trick users into clicking. ClamAV detection and ML classification strongly indicate malicious intent, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=navy+reserve+advancement+results+2020 PDF link annotation
    • https://cdn.sqhk.co/gixeruxa/ZqHhehf/31701414907.pdfIn PDF document text
    • https://cdn.sqhk.co/bukevexej/gfocjjh/high_resolution_abstract_images_free.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4495390/normal_605fe6542bcc6.pdfIn PDF document text
    • https://tofikopu.weebly.com/uploads/1/3/1/3/131381225/8384516.pdfIn PDF document text
    • https://cdn.sqhk.co/baluwofuk/ofHigQU/doodle_god_alchemy_walkthrough.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4487905/normal_6044dcb8aee55.pdfIn PDF document text
    • https://cdn.sqhk.co/guwuweri/h1ojGjh/run_3_unblocked_games_777.pdfIn PDF document text
    • http://italysummer.space/8-_7_practice_dilations_form_g_answersyq3kt.pdfIn PDF document text
    • https://toxupenowa.weebly.com/uploads/1/3/4/0/134042648/2b220b38614.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451574/normal_6020558098fd6.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4412900/normal_5fffc1116c11e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4486550/normal_600a1548118a0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4502268/normal_5fc7a07901a5e.pdfIn PDF document text
    • https://cdn.sqhk.co/jegamaxegev/g9fgcwU/93185765974.pdfIn PDF document text
    • https://fozaxuvuten.weebly.com/uploads/1/3/3/9/133986835/ff5facd.pdfIn PDF document text
    • https://doretufokisa.weebly.com/uploads/1/3/1/4/131438244/009472a8.pdfIn PDF document text
    • http://biweekamnf.com/63963216395hw3ja.pdfIn PDF document text
    • https://pagejenaxupiwig.weebly.com/uploads/1/3/4/3/134383440/4934772.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4472764/normal_5ff2cb87cc4a3.pdfIn PDF document text
    • http://evilcheats.fun/61105798452dq9e5.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://a3e8d6b6-68ee-4625-a313-a25a09dbd39d.filesusr.com/ugd/312e12_2db3349b227e458bba99cc42897dd4c0.pdf?index=trueIn PDF document text
    • https://790985df-dfec-4a08-b509-00f37668cf87.filesusr.com/ugd/a421e3_c17e2017f1c644b1ac847b9ae6676efd.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e5ac.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE5AC 5488 bytes
SHA-256: 29695e441ccc964a64b3f4b1880c659163d6d378705fecf48e7754df6efbe229
font_01_sfnt_off0000f851.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF851 10408 bytes
SHA-256: 8a9d2ce2234f8d5130ee96ecec97f86f2045c71b651185d37c63f7604af8342c