Malicious PDF — malware analysis report

Static analysis result for SHA-256 b132a4b15d2e3805…

MALICIOUS

PDF

75.9 KB Created: 2021-03-17 19:21:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-20
MD5: a0806f0d4d347d14eb9c2aab768289d2 SHA-1: b2350794e59730e1765dc8db647e50b3097483ba SHA-256: b132a4b15d2e3805b9b641baeb48cbae4bfae7cf091dedaefec0fc8f10e8d81b
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, many pointing to disposable hosting, and is flagged as a link farm. The primary URL, 'https://zajinet.ru/strik?utm_term=how+to+unlock+kwikset+smartcode+909', suggests a lure to trick users into clicking for information, which is a common phishing tactic. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=how+to+unlock+kwikset+smartcode+909 PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4457839/normal_60265af07151e.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4410717/normal_5fcd56d773f90.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4463526/normal_6035a6eb6189f.pdfIn PDF document text
    • http://kurs1.xyz/how_much_is_a_wii_u_at_walmartbp98w.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4450037/normal_5ffc1f610b3f0.pdfIn PDF document text
    • http://donbetosstreettacos.com/joyeux_noel_splat_ce1hyk6w.pdfIn PDF document text
    • http://ouily.xyz/the_miseducation_of_cameron_post_rating72yuc.pdfIn PDF document text
    • http://com-copyrighit.com/the_end_of_the_affair_1955_watch_onlinenfulp.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412908/normal_60462aa209074.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://4fbc56e1-d9a2-4996-be1d-38f9cd263936.filesusr.com/ugd/b1afee_94bc6be951c7476e96f90a6d3fd61560.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/05dbc521-fd8d-4b79-86d1-93d0ee8539bc/referenceerror_request_is_not_defined_javascript.pdfIn PDF document text
    • https://09d56968-2ae9-412d-ad86-e67dc63a1c23.filesusr.com/ugd/e8b91f_0fd3e32149184c05b6aacbe4da10ca9f.pdf?index=trueIn PDF document text
    • https://4edd92ed-4e96-4c3d-a837-a16c7246ae9e.filesusr.com/ugd/7c3149_af870af2829c4cd798f2d087f13da416.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/2525b040-ad11-4790-99a5-c05b2f859a63/what_is_the_ab_lounge_2.pdfIn PDF document text
    • https://1eb42bdc-3da6-4b32-b75f-4382f1721f8e.filesusr.com/ugd/35474d_c0a563b5e3024a609e2a8ba3469d37fc.pdf?index=trueIn PDF document text
    • https://0ef2f354-78a3-4528-990c-72f69c86fc6a.filesusr.com/ugd/6a0da6_74d282a1fae041db8fefbf50911730f5.pdf?index=trueIn PDF document text
    • https://b724dda4-e2e0-47c5-811c-ae3b7273578b.filesusr.com/ugd/a1e5ee_2a69d8d584c349a3b1064ec3e2d15ea8.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/9beae684-79a6-45c5-a131-c4248ef89927/jusejejikefik.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5da5e294-1fb5-47fd-a86d-01e3515165f7/suxekifiberulonufuke.pdfIn PDF document text
    • https://113c517c-d7b0-4b36-99d7-6722bcb7ef36.filesusr.com/ugd/8e66a5_2580e27ae8b04e9bbd5eb77000705f47.pdf?index=trueIn PDF document text
    • https://923a8ca3-316b-4844-b38f-9bc955ad4852.filesusr.com/ugd/312e0e_332edb3fd68b4e46a873cdbb940c56b6.pdf?index=trueIn PDF document text
    • https://2065f6f1-29fb-48ac-a230-4f4ab2d4b746.filesusr.com/ugd/b62953_836e364f18b143f083cf6c2fa2681834.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/de015ff9-1c80-419c-87af-2f998452aeeb/latest_celebrity_news_2021.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8cf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE8CF 5500 bytes
SHA-256: 053ba6589920a6279ba17bd28ddcbecb08742cbd9f04896530fda278e30926e5
font_01_sfnt_off0000fb79.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFB79 10896 bytes
SHA-256: 896385158cc206cdc04050671e66321fe4a6f3f86c877e20b04f3ef6c1c121de