Malicious PDF — malware analysis report

Static analysis result for SHA-256 8e9fb7742933f596…

MALICIOUS

PDF

74.1 KB Created: 2021-03-25 22:56:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 10b0dd36396ab686f0dfc5068bae317a SHA-1: 7b68cc0f961d5e2d5ad5d80426016b88311264b9 SHA-256: 8e9fb7742933f5968bb1d2d3b280d344180bef10ee7f6c7bb192dc70f62f875c
244 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file was identified as malicious by ClamAV and an ML classifier. It contains a large number of embedded URLs, many of which point to disposable hosting and are likely part of a link farm. One of the primary URLs, 'https://crophysi.ru/strik?utm_term=is+lexus+rx+350+7+seater', is flagged as a malicious redirector, indicating a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/strik?utm_term=is+lexus+rx+350+7+seater In PDF document text
    • https://rasuvore.weebly.com/uploads/1/3/4/5/134523398/ac4ea813d71.pdfIn PDF document text
    • https://zelekunidos.weebly.com/uploads/1/3/2/6/132682808/4cc1f474c5.pdfIn PDF document text
    • https://datagoso.weebly.com/uploads/1/3/4/7/134718767/7aab1502bf812.pdfIn PDF document text
    • https://nobiramiw.weebly.com/uploads/1/3/4/4/134403563/db024.pdfIn PDF document text
    • https://jonokiruvonanum.weebly.com/uploads/1/3/5/3/135319333/8ff1d2f32.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/e5c8fc32-52f2-4e6a-abfe-86b5b2076c39/8128982395.pdfIn PDF document text
    • https://332892e0-6a2b-40ad-946e-e7c92c61c867.filesusr.com/ugd/3e5d97_c2a5948ec76546d69eecd7d57e75ba4b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/82289f73-6844-461f-8228-22b2df64c5fe/20496656958.pdfIn PDF document text
    • http://rujujarorimepa.rf.gd/hernia_hiatal_deslizante.pdfIn PDF document text
    • https://b0b89e74-75d6-43b0-bb8f-fa2cd9bd5f5b.filesusr.com/ugd/b5ae3e_bb1e622ec2874ced87653f720b234703.pdf?index=trueIn PDF document text
    • https://6d23287f-a15b-43b7-8d69-700c0e01f504.filesusr.com/ugd/185c00_f03f9c4edd3b4c768129018f42500531.pdf?index=trueIn PDF document text
    • https://32e47638-7206-44c1-ad53-5c6f9176402e.filesusr.com/ugd/e00742_a742e48629cc46f4a3896a413f98f072.pdf?index=trueIn PDF document text
    • https://2dc0326d-ac60-47d8-bf46-f2dc9d334570.filesusr.com/ugd/21b4a7_e4762299e38845e883e401d8afdaf37a.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/ad755436-ee32-489e-9443-f4cb61487ffa/rinnai_code_12_problems.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ee7e0efe-0346-443f-a189-e2c4517d9fe0/grammaire_franaise_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5f8f1444-27aa-4407-8d44-916bf114c275/what_veggies_can_i_plant_now_in_florida.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2feaa906-b671-47de-8d49-8745a4753aa0/1476481722.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fe6b43db-4b21-4012-9b05-80a0fafe8739/osho_zen_tarot_free_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ff512674-61e4-4456-85ef-6e43b659e698/658406680.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7a058b66-53d8-4e8e-b442-40d521daa771/90433745192.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e4ad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE4AD 5192 bytes
SHA-256: e5b81461e0dfbfa19d28b2393f30d6ccc3f3dc067faadae7b9a55aa566c09efd
font_01_sfnt_off0000f670.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF670 10936 bytes
SHA-256: f167d520252adb723cc7415609c858561ddca551ae4453bb95836aaf704adcdd