Malicious PDF — malware analysis report

Static analysis result for SHA-256 bfa19c6ddfcfc8f8…

MALICIOUS

PDF

73.3 KB Created: 2021-04-21 15:44:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3c20239b4b8fe109025f71bdb832c885 SHA-1: b6f0b3d4e1e373c515192c758a35339d00764673 SHA-256: bfa19c6ddfcfc8f8ec97e413d3f354ec91ade84e84b095f7703cdf0ebc733bce
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file identified as malicious by ClamAV and an ML classifier. It contains a large number of external links, many hosted on disposable domains, indicating a link farm or SEO manipulation tactic. One of the primary URLs is `https://botokaw.ru/strik?utm_term=los+gramos+es+igual+a+mililitros`, which is likely the intended destination for users who interact with the document. The PDF structure and embedded content suggest it was generated by `wkhtmltopdf`, a tool often abused for creating malicious documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=los+gramos+es+igual+a+mililitros
    • https://doruxajowivabog.weebly.com/uploads/1/3/4/8/134870444/sizamikizotiki-mujivuna-zawutidalo-pekurigoxojig.pdf
    • http://ejqy.com/what_are_the_6_purposes_of_writingaiptj.pdf
    • https://vufomugivubi.weebly.com/uploads/1/3/5/3/135350936/sezabatuvaganam_tukota_nagidisusuwi.pdf
    • http://maxoranano.sportsontheweb.net/lageplan_center_parc_bostalsee.pdf
    • https://wuxivebumuvarog.weebly.com/uploads/1/3/1/0/131070366/2639886.pdf
    • https://lokeduvedip.weebly.com/uploads/1/3/4/8/134885922/bafukug.pdf
    • https://xoxekoxezugox.weebly.com/uploads/1/3/0/7/130738790/pilubifodipupagu.pdf
    • http://wirelessinfo.ru/76832246403o8ez.pdf
    • http://tdsevsvet.ru/62937622952838gz.pdf
    • https://vizodejow.weebly.com/uploads/1/3/4/3/134356937/6589147.pdf
    • https://wesuzimowigimeb.weebly.com/uploads/1/3/4/7/134745326/2458978.pdf
    • https://menanotiji.weebly.com/uploads/1/3/4/3/134322389/nijitepona-vokub.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://0524119b-9543-44d4-a9c1-6a2a85ae2681.filesusr.com/ugd/b12506_0030f89b5cf7451c9ac2da6c52088101.pdf?index=true
    • https://s3.amazonaws.com/mokuwanibof/63292077844.pdf
    • https://da5bec28-7969-4117-8ffb-5069fce5e80c.filesusr.com/ugd/31593d_7a4aeb3d01bf48cd9e029a145024c660.pdf?index=true
    • http://rinimodosejowuf.myartsonline.com/29507020963.pdf
    • https://s3.amazonaws.com/webipejonavuv/34857227022.pdf
    • https://aefbb2f1-1cfc-4a48-aab2-d72547d84173.filesusr.com/ugd/2f3ac6_7b9e55985e654a2d89964dea2db61b23.pdf?index=true
    • http://korofituzuxigu.onlinewebshop.net/python_anaconda_tutorial.pdf
    • http://zepizevut.atwebpages.com/hymn_barclay_james_harvest_noten.pdf
    • https://dbba0f06-1911-40f0-8c80-a2638c7f81cc.filesusr.com/ugd/b13fd1_6ff7c41a6d6344f796c9f25d549414d7.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ddce.bin
9109bbac15fae08ea56dce0837e8c09a134446888097abd80a5e29a31dc4efd4
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDCE 4948 bytes
font_01_sfnt_off0000ee90.bin
d3fda9fffa2cc84c8ce1845469706404047d8c209d0115d14904cce55b7329f4
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE90 12784 bytes