Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0cf43301323f12e…

MALICIOUS

PDF

68.3 KB Created: 2021-03-31 11:48:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-20
MD5: aea1b88db033c0f35f4629c21f3035f4 SHA-1: b5676370e5b8b894675d8d089788de7c22b698ab SHA-256: e0cf43301323f12e14f6560ba9c937639aaf23d34e48a236cf9f67a705bc6322
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, identified as a 'PDF_SEO_LINK_FARM' and 'PDF_SEO_UTM_REDIRECTOR_LINK', suggesting a phishing or malware distribution scheme. The primary redirector URL is https://ponafet.ru/123?utm_term=jquery+select+submit+button+in+form, which likely leads to a malicious payload or phishing page. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/123?utm_term=jquery+select+submit+button+in+form PDF link annotation
    • http://confirmyourverifiedbadge.com/how_to_figure_out_a_redox_reactionzkd9i.pdfIn PDF document text
    • http://newyearshop.site/kixiruwowupuviwumiziz7op4.pdfIn PDF document text
    • https://cdn.sqhk.co/fusozuwalas/fgPAhdn/rom_manager_apk_pro.pdfIn PDF document text
    • https://cdn.sqhk.co/nakunadubux/x9xUia9/the_best_disco_songs_80_s.pdfIn PDF document text
    • http://lodemazupunogas.iblogger.org/advanced_excel_formulas_with_example.pdfIn PDF document text
    • https://cdn.sqhk.co/varugefezum/QZoic5K/tokepodif.pdfIn PDF document text
    • https://cdn.sqhk.co/sipebesoxu/gjpcJjg/tozogivubimafoduvoge.pdfIn PDF document text
    • http://ompala.store/228400694041iv0f.pdfIn PDF document text
    • https://cdn.sqhk.co/vupapevixu/LibrFh1/ledufojisimon.pdfIn PDF document text
    • http://ceiling48.ru/vowewabodugajijosakemezo3zljq.pdfIn PDF document text
    • http://nakidki-alkantara.xyz/9830038396131okv.pdfIn PDF document text
    • http://digitalcalakk1.xyz/heil_furnace_pilot_light_wont_stay_litx9yj4.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://c02a3fa2-970f-4384-b4fa-7a60184a1b73.filesusr.com/ugd/1da3fe_42caef80b34345f5a026966fd093959d.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/lunojol/28727535791.pdfIn PDF document text
    • https://s3.amazonaws.com/laradusa/99118038403.pdfIn PDF document text
    • https://s3.amazonaws.com/wujixus/minosajesufizakolo.pdfIn PDF document text
    • https://e924225a-aa46-4bfc-8e56-7341551e1833.filesusr.com/ugd/54dfea_6b7f83b537a746c69d88b95ed49e4b02.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/xeroguru/adjectives_worksheets_for_grade_2_with_pictures.pdfIn PDF document text
    • http://voxedolap.epizy.com/23121021837.pdfIn PDF document text
    • http://muvidunijusen.rf.gd/difference_between_cruise_missile_and_ballistic_missile.pdfIn PDF document text
    • https://s3.amazonaws.com/zobuwubedak/benedurozururifu.pdfIn PDF document text
    • https://aeedc83c-a41d-4179-9d48-e770e4c4cd47.filesusr.com/ugd/e010a7_6d790a4e41624a7a89159d9c8a6d62ec.pdf?index=trueIn PDF document text
    • http://rivapuremamoge.epizy.com/zemaw.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ccbe.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCCBE 5172 bytes
SHA-256: c6564fe4b42e9bcfba7eaccfc7b807d0344e48dc783d6391f2a7a64151f9cb10
font_01_sfnt_off0000de55.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDE55 10916 bytes
SHA-256: 56e1349ea5e70009216c50d6b34479d66f3987303b8f6a1fdc9cec39bc89691a