Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b758702207e8575…

MALICIOUS

PDF

77.7 KB Created: 2021-05-28 21:46:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 224d7f46163682c574ce454bd35c49b6 SHA-1: 1097322566d031c6e6c59aaeac7c82a9088040ff SHA-256: 8b758702207e8575a4983007cdd2717a4d43c5aa1e7f95c22239f2134b2bf30d
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with one pointing to 'xajibur.ru', a domain flagged as unknown. Heuristics indicate this is a link farm on disposable hosting, suggesting a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to a phishing campaign or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/strik?utm_term=sin+senos+si+hay+paraiso+temporada+2+capitulo+37 PDF link annotation
    • https://lukazerud.weebly.com/uploads/1/3/4/3/134343231/mapesatezamapegigas.pdfIn PDF document text
    • https://gewaxuselez.weebly.com/uploads/1/3/4/2/134265722/bejixefizupotozove.pdfIn PDF document text
    • https://bivamotitujodo.weebly.com/uploads/1/3/4/7/134712473/5456568.pdfIn PDF document text
    • https://feditesar.weebly.com/uploads/1/3/1/4/131483001/097f2c52f.pdfIn PDF document text
    • https://tagarimoruta.weebly.com/uploads/1/3/4/3/134320697/e2afce15e516c.pdfIn PDF document text
    • https://telixezudaridif.weebly.com/uploads/1/3/0/7/130775339/mokuwanaworuko.pdfIn PDF document text
    • https://xifamileg.weebly.com/uploads/1/3/4/6/134687686/e982e85e1b.pdfIn PDF document text
    • https://towelekuw.weebly.com/uploads/1/3/1/4/131406253/ratomuzuxikevevop.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/d65a6302-74ef-4cc3-b0ca-8b667a5f037f/80025259222.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bafb9a08-07b1-4362-ada5-30835238c9cb/how_to_hack_clash_of_clans_iphone.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/91018144-576c-48bb-a3a3-bbf1c4165112/how_to_interpret_ir_data.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ee525432-ccbc-4115-9f38-7b1709aaee90/nanesoxositifer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dc956973-7f55-4558-afe8-8f5ab775c56a/flir_one_user_manual_android.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/56daafa2-b87b-4711-bbc3-75bd6a52e856/jeterixove.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c09a9a9a-1060-4fcc-83ab-ab1a24847e59/kenneth_hagin_healing_school_youtube.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/34ab53b9-0156-4f92-abf0-96bcba1b7aa5/najavukuwapisitifagos.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/711fa9e6-455e-4805-b63b-2a8d1220d59b/kajemanaradugadelunak.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2389bc1b-1390-4eb1-a1c9-297b0496a87c/an_enquiry_concerning_human_understanding_amazon.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9480787e-74aa-404b-96f0-6a6f842d3072/xidobolejukoxatu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b4eb5c9d-7a8b-4a46-9992-0f3bcfad4c55/jawidoterujonodeputafogap.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8870662f-64d1-4fe3-b0a5-5bb7a783dc8b/witotinudulub.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/57098cb7-0cc6-4470-9c95-46d3000bdc00/55997622135.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a9683425-077b-4aa2-93d6-6deac97856f9/healthy_smoothie_recipes_without_milk_or_yogurt.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/38cf1ee3-bf66-4a1b-9249-7127c8f0ec8c/mass_flow_rate_calculator_english_units.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eeae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEEAE 5892 bytes
SHA-256: 9efccd94139a3e1c0e4e68c0a1521f88a18455f2a01ddb3b435386980bbbf15d
font_01_sfnt_off0001029f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1029F 12608 bytes
SHA-256: 74300a93ac9c2e36779c9fec2c06d580a665a74e7fdf42c307b1f7a206b5055b