Malicious PDF — malware analysis report

Static analysis result for SHA-256 f0a5ba292c368d22…

MALICIOUS

PDF

80.5 KB Created: 2021-03-20 00:01:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-13
MD5: 73e6f82fb185e480416879226f1e319b SHA-1: d58d6d497ef7eb81e66dc02fbdfb3cd3bba8cf1f SHA-256: f0a5ba292c368d22dd603c32d8b46b1fe669751a276019324a7a08ba55447c8f
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains a large number of external links, many hosted on disposable domains, suggesting a link farm used for SEO manipulation or phishing. The document body, though heavily obfuscated, appears to be a lure related to a game achievement guide, directing users to external URLs like https://ponafet.ru/wix?keyword=xcom+2+heavy+metal+achievement+guide.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/wix?keyword=xcom+2+heavy+metal+achievement+guide PDF link annotation
    • https://durunefa.weebly.com/uploads/1/3/4/7/134712847/kikogamo_baxarujenazafe.pdfIn PDF document text
    • https://zowololo.weebly.com/uploads/1/3/5/2/135294949/9850196.pdfIn PDF document text
    • https://nuduxojobiri.weebly.com/uploads/1/3/4/6/134629521/7872134.pdfIn PDF document text
    • https://ziwuvofoxovexo.weebly.com/uploads/1/3/1/1/131163777/jezanawazafidaboxif.pdfIn PDF document text
    • http://magnifioco.site/75537783362vm0di.pdfIn PDF document text
    • http://itslm.fun/bullying_causas_y_consecuenciasvp56a.pdfIn PDF document text
    • https://wifiluguzuz.weebly.com/uploads/1/3/1/4/131437957/tadodubazeti_serugexibu.pdfIn PDF document text
    • http://changepass.online/instalaciones_gas_natural_vehicular_bogotak7nj8.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://5f90d536-2a72-4461-adff-280afd3056cb.filesusr.com/ugd/27c394_7c01f24a925b40e58b267a40e96ffb2d.pdf?index=trueIn PDF document text
    • https://a40b6db0-1679-4e03-879f-ac5827b9aa7d.filesusr.com/ugd/dba42a_c75c6c731ff54f9b86f9f21d86266365.pdf?index=trueIn PDF document text
    • https://b6de9e3f-c562-4e05-b5ee-70895c8060ae.filesusr.com/ugd/3801ff_510e774f5fd44d88b2522c29d1c389d5.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/59f8177d-b992-41cb-b886-fc67668193ca/financial_modelling_course.pdfIn PDF document text
    • https://14319df0-7947-4f0d-bbb3-eaa17d5eb23e.filesusr.com/ugd/c45f38_b7ed86a067214749953ef825d678bf56.pdf?index=trueIn PDF document text
    • https://c0771fee-1ba5-4dbf-bba5-a775c3d44c03.filesusr.com/ugd/544e7e_fc332b7b813c46d5bab057a4988372e4.pdf?index=trueIn PDF document text
    • https://5b949be5-44ef-49af-96c7-0ebaa8fe632e.filesusr.com/ugd/3402b1_4b32d820ed66476aac5414d57f2478ad.pdf?index=trueIn PDF document text
    • https://8ecf7690-1f99-4e28-a4b6-3228ba9731d7.filesusr.com/ugd/63d3ad_52407f07faf249f58c1c388f39060e28.pdf?index=trueIn PDF document text
    • https://df9f6e4b-8d15-4ffc-a22d-a689b54aa2df.filesusr.com/ugd/205ae4_46294fba6a1348d2a86d6dc8685d3443.pdf?index=trueIn PDF document text
    • https://e5aadbcf-511f-4ee2-989a-4410a22eeed0.filesusr.com/ugd/64930c_46aa98bd1c984317b9a655c83bee0ebd.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/cc6775eb-6723-4d93-8a26-9fbfd315f26f/lg_washer_maintenance_manual.pdfIn PDF document text
    • https://5b0e1d79-1acc-45ba-a965-31015372eee8.filesusr.com/ugd/67f5f7_39d630f577ae49a496ba78fb4a267477.pdf?index=trueIn PDF document text
    • https://e06e8306-d71e-4c92-aa1b-e8c52eeb44cb.filesusr.com/ugd/bc4951_41a2a1568c654004b5e385e26a107de8.pdf?index=trueIn PDF document text
    • https://84d655c4-d84a-4a0c-9c32-0387925bd622.filesusr.com/ugd/6233da_f8ddc59d7c8844e8820e5a84b7f3e283.pdf?index=trueIn PDF document text
    • https://f459ab6e-ac57-43ce-b83a-1524846427e4.filesusr.com/ugd/938c70_bbcce96f3e404220b66362736c7895ec.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fecb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFECB 5352 bytes
SHA-256: cf640a24caa1c8e0e46ecd0ba1175be80a057ff6e954e1a9e51fcfd128f4d222
font_01_sfnt_off000110ea.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x110EA 10484 bytes
SHA-256: 73a4ac38515148ee4768f04b59081723b4a6b0344a9e1845f96e8f5c2637922f