Malicious PDF — malware analysis report

Static analysis result for SHA-256 936cff07f7cc77fd…

MALICIOUS

PDF

83.9 KB Created: 2021-03-29 17:32:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 405eaabd56e8ebfcce9a1413b1f4c914 SHA-1: e2f96d70148659b8447f391e5108b58086453f65 SHA-256: 936cff07f7cc77fd866cf77b89487a1f005913ff8681b9afcbf834912f7073cc
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, forming a link farm, and is flagged by ClamAV as Pdf.Phishing.Trojan. The embedded URLs suggest an attempt to redirect users to potentially malicious or spam-related content, likely for SEO manipulation or phishing. No scripts were extracted, but the PDF structure itself is indicative of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/award?keyword=que+son+los+habitos+alimenticios+pdf PDF link annotation
    • https://wewiruvikaju.weebly.com/uploads/1/3/0/7/130775929/deparedelapari_tunovujaz.pdfIn PDF document text
    • http://about-igsupport.com/earnings_per_share_questions_and_answers0047r.pdfIn PDF document text
    • https://gefizubumob.weebly.com/uploads/1/3/4/4/134473977/xisarefefuzinik_baruvulurigisij_xeboledam_bisen.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4372982/normal_5fe5472c0533a.pdfIn PDF document text
    • https://xesudubivutomu.weebly.com/uploads/1/3/5/3/135303490/738419d887fd014.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4413967/normal_5fedcecd9378a.pdfIn PDF document text
    • https://felanixumuxovex.weebly.com/uploads/1/3/4/7/134705369/zijovasarigulalat.pdfIn PDF document text
    • http://batmbatm.ru/monopoly_cheaters_game_guideyds55.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4411717/normal_601dae53a36c3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4480899/normal_603e2c59c6279.pdfIn PDF document text
    • https://dejutuzalusabi.weebly.com/uploads/1/3/4/8/134869317/kunaxaxopatotugivaf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4453550/normal_5fd6292c5cd37.pdfIn PDF document text
    • https://fagowegegex.weebly.com/uploads/1/3/5/3/135315381/1278073.pdfIn PDF document text
    • https://mifafipuwekirej.weebly.com/uploads/1/3/5/3/135327035/juvavapipok.pdfIn PDF document text
    • https://gidepojijozi.weebly.com/uploads/1/3/4/2/134235950/76523a2aabd.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://fb7bf4c5-056f-4058-a7d1-073478569b53.filesusr.com/ugd/d90490_307489a7814f427aab8bb4ec74cea451.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/aea7629b-388a-48c6-924e-24c957b33105/descargar_biblia_textual_completa.pdfIn PDF document text
    • https://3a5aa097-47f9-475f-9992-83bceef25cc3.filesusr.com/ugd/f55bec_eb68e3d0e79140f0ac072dd4785035e2.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/d571f507-9d06-492c-90e6-144d124dfb99/4918106083.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6a7b570b-fa02-4f0c-b1f7-e4994b3a9e41/60248454216.pdfIn PDF document text
    • https://404c0e03-56c4-4888-bb84-d9d32a71a3e4.filesusr.com/ugd/100e2e_b9d3430f8e754bc290e1b35a575ab208.pdf?index=trueIn PDF document text
    • https://5a8aee2d-3d68-4c09-98ed-743c9c56d6fd.filesusr.com/ugd/460efe_afeca6b729fe4612b1bc2775df5e0a96.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/7eb11c9b-93ea-49db-aa11-5ba189d5f13f/do_restaurant_workers_get_free_food.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4e34e186-1cec-474e-9bd3-9e0856efce9d/how_to_activate_function_keys_on_lenovo_laptop.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f92c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF92C 5380 bytes
SHA-256: f04654e17b20de578a31700ee743df58b0d2fb845f169b4e21853834727c0c8a
font_01_sfnt_off00010b43.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10B43 11792 bytes
SHA-256: 441a01b08dfbdf2af4b20341a296e1f5402d01b0552ad2430dd35ed469a52b4a
font_02_sfnt_off00013192.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13192 4324 bytes
SHA-256: ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230