Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f36115a1d1508a6…

MALICIOUS

PDF

88.5 KB Created: 2021-03-23 09:47:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: 4f59498ed32b247ce9427e8995a805e9 SHA-1: efb75b14532e002cc2ab4e905eda82d5c753da7c SHA-256: 7f36115a1d1508a6e6add247eefc05d894af2be83880c2ef42c4be8227584acc
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a common tactic for SEO manipulation and link farms, as indicated by the 'PDF_SEO_LINK_FARM' and 'PDF_SEO_DISPOSABLE_LINK_FARM' heuristics. The primary external URL, 'https://gimoguvi.ru/award?keyword=asian+literature+history+pdf', suggests a lure to a potentially malicious site. ClamAV detection and ML classification strongly indicate maliciousness, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/award?keyword=asian+literature+history+pdf PDF link annotation
    • http://nadefememidep.medianewsonline.com/does_sodastream_really_work.pdfIn PDF document text
    • http://lukufogud.getenjoyment.net/aircraft_structures_2_notes.pdfIn PDF document text
    • http://wivaserana.mywebcommunity.org/positive_thinking_techniques.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4500911/normal_6055877d77763.pdfIn PDF document text
    • http://sowipilarow.mygamesonline.org/hp_officejet_pro_8600_plus_ink_cartridges_depleted.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4408879/normal_5ff5235496767.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4418192/normal_5feba497213e6.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4380525/normal_5fff087bde8a9.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/9177ff54-561d-4a35-b3fa-681a2b026178/reguxukodapapebeju.pdfIn PDF document text
    • https://121f8fc1-d270-4171-a721-8ccd656fc20f.filesusr.com/ugd/2ca22b_3f765fddf62b4cfe9d3468329ac8e70f.pdf?index=trueIn PDF document text
    • https://6a1e2a5f-c456-4288-b9d5-5378f87870fb.filesusr.com/ugd/076fac_a16d4d32b4a3483fbbb48d1f5b418f61.pdf?index=trueIn PDF document text
    • https://f730d15c-1921-46d2-b6d4-288333e40990.filesusr.com/ugd/e2c223_78f75999e9514062b58419b74001fe38.pdf?index=trueIn PDF document text
    • https://28ae28a3-27cc-4d38-be83-0de1f6925f83.filesusr.com/ugd/454016_2689e87ed48d4969b69fefa218d468dc.pdf?index=trueIn PDF document text
    • https://2cfcb734-ec62-4cd9-b61c-03d4762ad765.filesusr.com/ugd/a891c0_75897f898bd34b09b9bd017ef4d55f98.pdf?index=trueIn PDF document text
    • https://11210a16-d5d1-4e17-93a3-27fbbb12f21b.filesusr.com/ugd/fb658e_c03a56fa7fe64385ade573c969e96c4b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/26ed2628-db58-4437-8d02-e9a1b2841dfe/fawuvumexokizosizekul.pdfIn PDF document text
    • https://69a21580-3c80-4f81-8097-1ec0bc18215d.filesusr.com/ugd/bd7df1_f707b48cdb764b2f8be6c70933cf195a.pdf?index=trueIn PDF document text
    • https://77da94c0-0f0a-445b-87af-e489a0b5ef66.filesusr.com/ugd/db1da1_f911d5fb15564ef38491a00f09b7c9e2.pdf?index=trueIn PDF document text
    • http://vekabun.myartsonline.com/varicocele_tecnica_quirurgica.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ac1e906e-586f-4bda-bddf-143dd39c5261/evan_moor_first_grade_math.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/37dd3d9d-9f8d-450f-981c-540d6cafc7b8/how_much_is_sandalwood_worth.pdfIn PDF document text
    • https://c145ee04-3c3b-4786-8b94-e0511401b322.filesusr.com/ugd/de65f7_99e659bb81304ac784d41a3f768d6081.pdf?index=trueIn PDF document text
    • https://e0220c8c-c322-4c33-af83-7c5b0fe00b66.filesusr.com/ugd/a771bd_c1423e03dae749a3b61dcd8075e27183.pdf?index=trueIn PDF document text
    • https://1f49b3f1-4b09-4f89-88df-03804352fc9a.filesusr.com/ugd/a51aec_3425bca2fc2643cbb71f2648aab94b51.pdf?index=trueIn PDF document text
    • https://dacf5b84-f80e-4bd8-bb7f-22aad20a1cd8.filesusr.com/ugd/285be4_cce652444fd645469c73cc21746bc028.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011ef7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11EF7 5220 bytes
SHA-256: 91c8d9dec2c522c9d324b7bed3589d09c209d1613e23bbb00dac619076fd326d
font_01_sfnt_off000130bd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x130BD 10504 bytes
SHA-256: daeab403da67b5cce8dcb424b421295e5dc41c448a7dbc7bc691a41ad98ccabe