Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee48fd1e3ae17ff2…

MALICIOUS

PDF

86.9 KB Created: 2021-03-06 18:41:28 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: b82d70efc360d1528096c78b0f52b781 SHA-1: 5a1cb40334aaf5027f2c0b2ffcac1a74508eae9a SHA-256: ee48fd1e3ae17ff2e796bb540b298609b58d26c336b07fdc6755027cb4d7604e
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document was identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a large number of external links, with one pointing to `https://midufefew.ru/strik?utm_term=tp+link+wr841n+manual`, suggesting a link farm designed to redirect users to potentially harmful content. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic strongly support this attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/strik?utm_term=tp+link+wr841n+manual PDF link annotation
    • https://pexevirojaloko.weebly.com/uploads/1/3/4/8/134882405/jaxutekudisokaxejib.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366057/normal_602bdaae728f4.pdfIn PDF document text
    • https://gafonubizaragu.weebly.com/uploads/1/3/5/3/135346264/wimokufaxoja_xulukemoropifog_kowulekimob_getekesabexuf.pdfIn PDF document text
    • https://zewelujipe.weebly.com/uploads/1/3/4/8/134846298/xuvoluwadim.pdfIn PDF document text
    • https://lopenedaxi.weebly.com/uploads/1/3/1/6/131606218/bfb3f19221c.pdfIn PDF document text
    • https://telisawe.weebly.com/uploads/1/3/4/4/134466193/6297312.pdfIn PDF document text
    • https://cdn.sqhk.co/kidimezamos/jiiigJE/free_followers_and_likes_apk_download.pdfIn PDF document text
    • https://cdn.sqhk.co/kisesawaropo/rgj5ihi/foxone_gratis_mod_apk.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4422643/normal_5fed1cff4e6ce.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4372358/normal_6038ed8d3bf6d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4475570/normal_602ce57ddc5ec.pdfIn PDF document text
    • https://cdn.sqhk.co/pirasemofoge/x8iefb6/81070451952.pdfIn PDF document text
    • https://cdn.sqhk.co/vuvesanap/iiEyhbd/yellow_cab_pizza_menu_flavors.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://4d75d3c9-3a4d-4df6-84ab-e48b83d723e5.filesusr.com/ugd/cdb50c_2794961fdd4848748bf12ef5bc0dac2e.pdf?index=trueIn PDF document text
    • https://9534cc33-30dc-483d-bed2-8d5691710d48.filesusr.com/ugd/3835dd_e5a604b9f0b04587a615c0aaed4f567c.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/3d7e057f-f8ea-417e-a072-870181751953/roxogoxavofedodepupu.pdfIn PDF document text
    • https://a7193630-a032-4ee2-b136-33837135b76a.filesusr.com/ugd/fac845_3048b1f0de9f4eccadb0d64a68c02c64.pdf?index=trueIn PDF document text
    • https://52c77544-2eb8-427c-ad0e-a8a7e2ea9366.filesusr.com/ugd/93288f_dbdaf5e66656443cb62ae3647d59dd07.pdf?index=trueIn PDF document text
    • https://01d7ec8a-e38e-4e33-8c76-1be31754498b.filesusr.com/ugd/24d943_d5014ab7160b4b0a89929060da3901cc.pdf?index=trueIn PDF document text
    • https://abee6ad4-cf47-459a-954e-22b9b9bb30ad.filesusr.com/ugd/4bdc6d_255b529d60af43db97e55976ac9442ff.pdf?index=trueIn PDF document text
    • https://d9226533-59f4-4737-ae77-cfa9cdee5378.filesusr.com/ugd/d7c203_bd95b7e1bcc340ad8ff2fa3c32f200d2.pdf?index=trueIn PDF document text
    • https://1b15a19f-c8c2-4d9d-8c2f-e97aa7ecfe2c.filesusr.com/ugd/eb6c48_a186315ea4cc4325b415daabd1e9c773.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/915f36d6-12d5-460d-9c7b-14e6b29f6906/an_ember_in_the_ashes_film_release_date.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2e1f1f09-b314-485d-8dc2-964dc36951a8/konirunenuliw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3868f07c-c10b-4849-9dfc-99175d7efca6/how_to_convert_midi_to_sheet_music_musescore.pdfIn PDF document text
    • https://a3de454e-1598-42bb-a259-4eb69c42f179.filesusr.com/ugd/fb5067_dc05422373d244a2b43b0fd9a5520d62.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/0ff8541f-0ee9-426b-9a8a-e7e533410ed9/88494424136.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000109ca.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x109CA 5228 bytes
SHA-256: 361b83f22ddad3e375184057992ef647785a05f19019efc8a50a4f59c59ad9ec
font_01_sfnt_off00011b95.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11B95 17104 bytes
SHA-256: 83c39e1cfbd2246c6ad8fa770c663f376b772ddef2039d664fe90d61ffa5dcbb