Malicious PDF — malware analysis report

Static analysis result for SHA-256 5cda2ff37be2489a…

MALICIOUS

PDF

87.5 KB Created: 2021-04-23 19:14:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 8990941f49a714e2c5a873645961c1dc SHA-1: e0fbef2ae4c6fd017bf047a9ac5f4d85fee8cb26 SHA-256: 5cda2ff37be2489a29d00fbd005cedf4bad543af8be05841cd9782494a7daea1
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many hosted on disposable domains, suggesting a link farm or SEO spamming operation. One prominent URL, 'https://midufefew.ru/strik?utm_term=dd-wrt.v24+mini_generic.bin+download', appears to be a lure for a software download. The ML classifier strongly flagged this PDF as malicious, and the heuristic firings indicate a link farm designed to distribute content, likely malicious, through numerous external URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/strik?utm_term=dd-wrt.v24+mini_generic.bin+download PDF link annotation
    • http://pofuxubilet.sportsontheweb.net/akhund_darweza_baba.pdfIn PDF document text
    • https://gulipuzajetag.weebly.com/uploads/1/3/5/3/135397689/dilinenibe_lubaweza_wegobu.pdfIn PDF document text
    • https://dovapudatanul.weebly.com/uploads/1/3/5/9/135985540/6553507.pdfIn PDF document text
    • http://somixewavado.sportsontheweb.net/john_deere_js63_diagram.pdfIn PDF document text
    • http://lavka-karamel.ru/tomutudokiwacx646.pdfIn PDF document text
    • http://zumewidife.mygamesonline.org/possessive_adjectives_explanation.pdfIn PDF document text
    • http://dreamingdeveloper.com/8716091694zz934.pdfIn PDF document text
    • https://fusofopafufet.weebly.com/uploads/1/3/5/2/135294951/sogaritedofudixe.pdfIn PDF document text
    • http://changepass.online/ukulele_strumming_patterns_4_4d4fg6.pdfIn PDF document text
    • http://medgaj.com/27228532492oc0u1.pdfIn PDF document text
    • http://goxamid.mypressonline.com/72649430506.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/0e97fc42-18fb-4221-99c8-df0f683f4cfd/is_it_legal_to_marry_two_wives.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1f28fc80-c0db-4aa7-a7e2-791cdce1d3a6/who_animated_one_punch_man_season_1.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/88d00f1c-b5f2-4ea8-b486-d991df6876d2/nalonulivixewel.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/469190ba-751b-42e1-b509-69f69a5138d0/metamorphosis_kafka_movie_online.pdfIn PDF document text
    • http://zugepoguj.onlinewebshop.net/english_aptitude_test_questions_and_answers_free_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/63bd91a6-71fe-4c15-b3f0-b5b2b49ed5c6/how_to_fit_integrated_dishwasher_door_bosch.pdfIn PDF document text
    • http://rijonitapadon.myartsonline.com/cisco_4742hdc_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9148ddfa-c450-439f-bcba-b036467d088c/guess_brand_logo_level_212.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b56fbc0d-64d1-44fa-ad2a-867028ffb9c1/physics_assignment_class_9_answers.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/feb99536-c655-4152-9395-1d8596416ab7/samsung_55_inch_qled_tv_weight.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2919e78c-a5a9-48ed-a365-8be53c7e6868/the_gospel_of_thomas_youtube.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1f6fdc60-dc64-4759-bc0a-cff9a3840839/2010_lexus_rx_350_cargo_space.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb29.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFB29 5472 bytes
SHA-256: 9bffe208506e11b11056e9ac5a0aad145e2e948bf71ae1107ae4188413186800
font_01_sfnt_off00010ddb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10DDB 23128 bytes
SHA-256: 9bcae257099423bad617c5a023ed56f47102754cd7711d1416c55856fd41c9c7
font_02_sfnt_off0001425e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1425E 4324 bytes
SHA-256: 0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333