Malicious PDF — malware analysis report

Static analysis result for SHA-256 71850ab66769f9a6…

MALICIOUS

PDF

77.2 KB Created: 2021-05-24 00:27:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e4594468a1a6c0daa0e12851f6b733e8 SHA-1: 5b6053477fcd47edc6df7ef0bd48d5e6c63aec05 SHA-256: 71850ab66769f9a6c99e42921cfc2f92fcdf13f0b0e6a3094d0dad34f3e6d2e3
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, with one primary malicious URL pointing to dafemum.ru. This suggests the document is designed to redirect users to potentially harmful content or for SEO manipulation. While no scripts were explicitly extracted, the PDF structure and the presence of numerous external links are indicative of malicious intent, possibly involving JavaScript execution for further redirection or exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/strik?utm_term=how+to+be+a+fast+cashier+at+walmart
    • https://static.s123-cdn-static.com/uploads/4501996/normal_5fed2db9305b2.pdf
    • https://fogevama.weebly.com/uploads/1/3/1/1/131164507/xasulipupoxu-lanopeba.pdf
    • https://pulaberiboz.weebly.com/uploads/1/3/0/7/130775840/toxatixutarugove.pdf
    • https://mofizuzu.weebly.com/uploads/1/3/4/3/134316779/gebunonipurata_lonufapuva_mizikojafu_sefot.pdf
    • https://wetolobumusu.weebly.com/uploads/1/3/4/5/134579125/nixikivenasan-zosigajaxexo.pdf
    • https://wilulesutazi.weebly.com/uploads/1/3/3/9/133997377/xevenolap.pdf
    • https://sorebupewuf.weebly.com/uploads/1/3/4/4/134447244/kidawoluk.pdf
    • https://cdn-cms.f-static.net/uploads/4478137/normal_60148a3f5dc89.pdf
    • https://cdn-cms.f-static.net/uploads/4421050/normal_6016d0ee175b9.pdf
    • https://xivovawa.weebly.com/uploads/1/3/4/8/134875493/7228052.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/gekixadonuru/skyrim_black_books_in_order.pdf
    • https://s3.amazonaws.com/ganubifirigevi/soccer_manager_2020_0._1._6.pdf
    • https://s3.amazonaws.com/jozetej/search_engine_optimisation_seo.pdf
    • https://s3.amazonaws.com/daraniwekamidir/karanukanolez.pdf
    • https://s3.amazonaws.com/levovod/fubadujawupujigizaju.pdf
    • https://s3.amazonaws.com/tobaziw/dow_jones_30_day_performance.pdf
    • https://s3.amazonaws.com/bovenotojitowe/clarinet_free_sheet_music_popular_songs.pdf
    • https://s3.amazonaws.com/zuvovoxigumuz/22209909964.pdf
    • https://s3.amazonaws.com/gazitif/vawofujobopanotazomafekuz.pdf
    • https://s3.amazonaws.com/puretulenuza/wutabovo.pdf
    • https://s3.amazonaws.com/vifusupegiza/cascade_east_ride_center_bend_oregon.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f234.bin
42d3e7c1a86e6fdc5a5a23f69b0311a0969cf240a1655192b773a3e389f8441a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF234 5316 bytes
font_01_sfnt_off00010430.bin
fc41a27dea2f2944080d409c2159701668c8e8cf8ecd1b219e1b7da2f38deb69
pdf-font-stream PDF embedded font (sfnt) at offset 0x10430 10204 bytes