Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8d9e2ed79bce504…

MALICIOUS

PDF

64.0 KB Created: 2021-04-28 03:45:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 971e495a672c8376ca74f9bc7db60598 SHA-1: 6c0a44a1211feb939816ffdcf96ed95300890547 SHA-256: d8d9e2ed79bce504f3be75fc76bca347f3e2b4bf5ad0229b0326de94ab96a256
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains numerous embedded URLs pointing to disposable domains, a tactic often used for link farming or to redirect users to malicious sites. The ML classifier strongly indicated maliciousness, and the PDF_SEO_DISPOSABLE_LINK_FARM heuristic confirms the presence of a link farm on disposable hosting. While no scripts were extracted, the overall structure and URL distribution suggest an attempt to manipulate search engine results or distribute further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9610

Heuristics 3

  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=inkscape+crop+path
    • https://cdn-cms.f-static.net/uploads/4489428/normal_605c11d93a723.pdf
    • http://numusuri.22web.org/font_aksara_jawa_for_android.pdf
    • https://cdn-cms.f-static.net/uploads/4470979/normal_60157f1fbaa29.pdf
    • http://pumidafefisun.iblogger.org/amar_chitra_katha_ramayana_free_download.pdf
    • https://cdn-cms.f-static.net/uploads/4476416/normal_5fda7c5c4c31b.pdf
    • https://cdn-cms.f-static.net/uploads/4486350/normal_601c711129383.pdf
    • https://static.s123-cdn-static.com/uploads/4486748/normal_5febb5b394143.pdf
    • http://jekeluxuto.mywebcommunity.org/peck_atlas_of_human_anatomy_for_the_artist.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://f110cc6a-49d6-427c-9ab6-a3a4d323b004.filesusr.com/ugd/9e53d4_590c69dd48884463a2153e484da18346.pdf?index=true
    • http://putunoxixowelo.atwebpages.com/21563137963.pdf
    • http://gerogawotu.rf.gd/bncc_educao_fsica_ensino_mdio.pdf
    • https://7ec9ed57-df89-401a-953b-45744c150cee.filesusr.com/ugd/6e3131_8596937e3c364d6185ad90ce9bca6ad6.pdf?index=true
    • https://c6506652-bf5e-4f52-be36-03dbfaede22c.filesusr.com/ugd/f74919_417eacfc01334de4853f61553df66e92.pdf?index=true
    • http://zesafemumibow.myartsonline.com/ansys_tutorial_fluent.pdf
    • https://4f65703b-d4c0-4c9c-9e30-73c8cc83ec5d.filesusr.com/ugd/54fa57_f0c7c39f94354f83a0a55662200e7d51.pdf?index=true
    • https://0a3880f2-9bda-4900-b484-73a003b8a878.filesusr.com/ugd/3cbe5d_bb86db2090ae43e5992bb25e098c17b2.pdf?index=true
    • http://zaduzos.myartsonline.com/definition_of_business_research.pdf
    • http://wukevivetarapu.myartsonline.com/how_many_dc_rebirth_comics_are_there.pdf
    • http://dosibaguluf.epizy.com/the_dip_seth_godin_free_ebook.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f238.bin
da8a68712ec3a52163bc7367365f7e3c0eddfa5f44fc1f5545a8efe5c769c643
pdf-font-stream PDF embedded font (sfnt) at offset 0xF238 4732 bytes