Malicious PDF — malware analysis report

Static analysis result for SHA-256 c32afae8e8f03bbe…

MALICIOUS

PDF

78.1 KB Created: 2021-04-28 17:51:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-13
MD5: 751f8d9d0116be9554cba7e300dc532c SHA-1: 4f7aad23043c1e65677ba0bfa2c9fef2b118a9bc SHA-256: c32afae8e8f03bbebe0e1feec2619634019ca40ab1d1652b6f667090d3e5a4c9
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document is classified as malicious, exhibiting characteristics of a link farm designed to redirect users to external sites. The document contains numerous embedded URLs, including one that appears to be a search query related to knee exercises, likely a lure. The presence of a large number of external links and the use of disposable hosting suggest an attempt to manipulate search engine results or distribute malicious content through a network of linked PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/strik?utm_term=what+exercises+should+i+avoid+with+bad+knees PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4389376/normal_606e4760ee7a6.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4369927/normal_5fe2b8a6f118c.pdfIn PDF document text
    • https://tenekitu.weebly.com/uploads/1/3/4/0/134018212/jajeba.pdfIn PDF document text
    • https://cdn.sqhk.co/gidulikegel/hbhiJhe/manchester_by_the_sea_youtube_full_movie.pdfIn PDF document text
    • https://sadutixonigonu.weebly.com/uploads/1/3/1/4/131412491/b18b07d6ac3.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4369491/normal_5fca90b261507.pdfIn PDF document text
    • https://cdn.sqhk.co/rorexamuviz/gjMhejc/best_weekend_getaways_near_memphis_tn.pdfIn PDF document text
    • https://venozosuvizulul.weebly.com/uploads/1/3/0/8/130814909/cb56461909e911.pdfIn PDF document text
    • https://fibepuranes.weebly.com/uploads/1/3/4/0/134041348/da6e4631488b8.pdfIn PDF document text
    • https://zutofamofiselas.weebly.com/uploads/1/3/4/0/134040676/jebamiwupi.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4385012/normal_606e39a0599db.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4465255/normal_600174af85038.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://2f8a6ab9-e864-4757-b083-6627a13f4c48.filesusr.com/ugd/405339_a53d717b6a874592bb78a7244a2e3f68.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/povodijirig/58080667760.pdfIn PDF document text
    • https://564fd4a8-0e6d-4f97-813a-a14a70c45316.filesusr.com/ugd/f90d28_ff2061c03aac40718e71c006b8a37827.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/zupenafud/32159515179.pdfIn PDF document text
    • https://36071b1a-d853-4ad1-bccf-0ed894d94038.filesusr.com/ugd/906e9f_bb857355fec74afc8eb06e4dbae3b98c.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/sesijesule/asme_y14_5_dimensioning_and_tolerancing.pdfIn PDF document text
    • https://fb413987-6e77-4bf1-aaa6-e97eb550fbee.filesusr.com/ugd/108936_7e164b90d6784e0fa53272eaa8ad7aba.pdf?index=trueIn PDF document text
    • https://183cab0c-2e2b-44e6-b55a-0f82cb58e578.filesusr.com/ugd/133137_5f15b60c19ff40afa5f7f83c35cade8a.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/kuboki/carl_rogers_theory_of_self_actualization.pdfIn PDF document text
    • https://e4fb9bf1-a3d6-4767-9bf2-2a1021e5dc09.filesusr.com/ugd/53cfc7_2d85e6bbc7d14d0bb7c91858e5a8cab3.pdf?index=trueIn PDF document text
    • https://234a0c07-d908-4261-bb83-16b3c96a9b04.filesusr.com/ugd/73e0e6_02ba5a522a9f4113ada061d5f437b820.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f3c0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF3C0 5464 bytes
SHA-256: 317cae5f3e8cd2b0e183382203e4c71193259ffd72a3e4f7d3be344d615fa884
font_01_sfnt_off0001066e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1066E 10624 bytes
SHA-256: 06744a4a28d72ced7c5aa2efe1d2d936816f75b9f96ea74cf15c8f7a89c612bf