Malicious PDF — malware analysis report

Static analysis result for SHA-256 8dddfc8c157fc003…

MALICIOUS

PDF

81.4 KB Created: 2021-05-22 09:40:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4e50499a95b6498fd6381e288dd3a4da SHA-1: ad6eb028cc42f42ff0d43c4a79553edbef08aad4 SHA-256: 8dddfc8c157fc0037fcab6a1855cec572501b5d672520f737a623fc6236fad49
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The primary URL points to a suspicious domain ('kuzutuzo.ru') and appears to be part of a larger network of linked PDFs hosted on services like Weebly and Strikingly. This suggests a coordinated effort to manipulate search engine results or distribute malicious content through a link farm. No scripts were extracted, but the PDF structure itself is indicative of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=what+does+msv+mean+in+running+records
    • https://misiwutikamiba.weebly.com/uploads/1/3/4/6/134601431/2f823f8.pdf
    • https://turexebino.weebly.com/uploads/1/3/4/2/134265835/288445.pdf
    • https://murarukaxew.weebly.com/uploads/1/3/4/6/134666391/befar.pdf
    • https://voteweze.weebly.com/uploads/1/3/5/3/135346586/9613514.pdf
    • https://static.s123-cdn-static.com/uploads/4369179/normal_5ff5e4c77fa3b.pdf
    • https://palisuxil.weebly.com/uploads/1/3/1/0/131071308/5982617.pdf
    • https://geridaradekod.weebly.com/uploads/1/3/1/4/131437552/23e84.pdf
    • https://dedemapisiwopiv.weebly.com/uploads/1/3/0/7/130775251/fivuleroti-xebifodolabeja.pdf
    • https://static.s123-cdn-static.com/uploads/4453105/normal_5ff006681a330.pdf
    • https://cdn-cms.f-static.net/uploads/4377128/normal_6042f7084bfcc.pdf
    • https://cdn-cms.f-static.net/uploads/4462732/normal_606e57d8f2635.pdf
    • https://rupusuji.weebly.com/uploads/1/3/4/8/134878943/sapemenewutas.pdf
    • https://wazumiwu.weebly.com/uploads/1/3/6/0/136038811/wedavesomuxoponikip.pdf
    • https://kagunalikabogow.weebly.com/uploads/1/3/5/3/135350350/jedepaletikuz-jaguju-wamedugakukipi.pdf
    • https://cdn-cms.f-static.net/uploads/4380531/normal_603e90247b4d5.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/a7015b77-e24e-42e9-b5d7-f5a7d4a4f281/fulezidujagoj.pdf
    • https://uploads.strikinglycdn.com/files/36cc6ad1-5f38-4884-838c-360807791d11/wigujigikomerova.pdf
    • https://uploads.strikinglycdn.com/files/71d3fa2f-3119-4862-8711-0bfb59815246/paint_by_numbers_for_adults_with_frame.pdf
    • https://uploads.strikinglycdn.com/files/9602aa93-c80f-4e3d-9eee-e0cdc8428e77/sat_math_score_percentiles.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ff60.bin
39b042e248d9975febe9c71c03d0d832ed1f12e456efbd621c69af8eee394df3
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF60 5392 bytes
font_01_sfnt_off0001119f.bin
81840363829c12fe43751bff385b62b5f2a2fbe36bdd7e5b22e47e04668e131a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1119F 10908 bytes