Malicious PDF — malware analysis report

Static analysis result for SHA-256 68035ce44cba8305…

MALICIOUS

PDF

74.2 KB Created: 2021-05-12 21:46:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 12b034ae12b2d0a54573833d453e4fc3 SHA-1: bfdeb3c3d20d62a776eabe4f3d672a1a686bdaa6 SHA-256: 68035ce44cba8305af4eb95334463a5b7b8f89d9b22d4ffffeb5ba0cf28da28d
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file contains a large number of external links, many hosted on disposable domains, suggesting a link farm or phishing campaign. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous external URLs suggest it is designed to redirect users to potentially malicious content, possibly for SEO manipulation or to host phishing lures.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8673

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/strik?utm_term=how+do+u+construct+an+equilateral+triangle
    • https://niwosegebopusa.weebly.com/uploads/1/3/4/5/134583118/rajajo_sawobopi.pdf
    • https://xapebetilozeze.weebly.com/uploads/1/3/0/8/130873864/4013668.pdf
    • http://wusokamojifel.scienceontheweb.net/tecnologias_de_informacion_y_la_comunicacion_libro_book_mart.pdf
    • https://nulesurusisozi.weebly.com/uploads/1/3/4/7/134744420/b9d82e78f.pdf
    • http://egrn-order.online/vrml_viewer_5._1fjj4w.pdf
    • https://jekewuvewaw.weebly.com/uploads/1/3/1/0/131070420/797a97.pdf
    • http://jekeluxuto.mywebcommunity.org/geometric_symbols.pdf
    • http://car-den.ru/black_wii_model_rvl-001vbldg.pdf
    • https://muxolebutelun.weebly.com/uploads/1/3/2/7/132741382/dimejiveminow_xegufubiperezoj_tozutonixab_dulolosi.pdf
    • http://nedavupagisezim.mygamesonline.org/71135455161.pdf
    • https://rufekelikofevav.weebly.com/uploads/1/3/1/0/131070689/lofeso.pdf
    • https://jajozopikikaju.weebly.com/uploads/1/3/4/3/134359408/wuzatupogogezuz_sexogoki.pdf
    • https://cdn.sqhk.co/nenakowi/dxUgjji/ar_zombie_shooter_survival_apk.pdf
    • https://faxulifil.weebly.com/uploads/1/3/4/7/134731484/6625121.pdf
    • https://lakofanagobogan.weebly.com/uploads/1/3/5/3/135386994/nesil.pdf
    • https://cdn.sqhk.co/jojikoxazew/jaQcijZ/52983574698.pdf
    • https://cdn.sqhk.co/nobixapo/xjcgcx1/8261161105.pdf
    • https://gabodubelekopo.weebly.com/uploads/1/3/4/3/134356924/gosanikiduvefa.pdf
    • https://cdn.sqhk.co/junulevi/cy7khdo/monster_shooter_2_back_to_earth_apk.pdf
    • http://opssmall.space/livre_de_regle_warhammer_40000_v8qe8rr.pdf
    • https://kezunegewekal.weebly.com/uploads/1/3/1/4/131483031/kidepiri.pdf
    • http://moresukko.ru/losing_yourself_eminem_lyricsd6j7s.pdf
    • https://xitolomeka.weebly.com/uploads/1/3/4/0/134012462/vofepopakafisito.pdf
    • http://indohealth365.online/36458359973mj5up.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e88f.bin
142eba88eba2b50b21bf76b4572ae4cc1b374ed29986f3563f3bf2492e6db664
pdf-font-stream PDF embedded font (sfnt) at offset 0xE88F 5168 bytes
font_01_sfnt_off0000fa30.bin
69dedd27dbf4d96ed48ea91cc8d7f1dcc610d8670e28a761624dcf0304571e08
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA30 10848 bytes