Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1e8be78b1757807…

MALICIOUS

PDF

134.1 KB Created: 2021-03-10 01:18:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-13
MD5: 2487cf63bef977b94386776ad4b96dd4 SHA-1: 4e173f0bc41fce1c051c5b515659c96730fc6238 SHA-256: f1e8be78b1757807a6add94a5a7501ffb6d4b95e13fd1e7ef6cf74ecd5a70176
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs, with a primary focus on directing users to `https://kuzutuzo.ru/award?keyword=introduction+to+computational+mathematics+xin+she+yang+pdf`. Heuristics indicate this PDF is part of a link farm on disposable hosting, suggesting a phishing or malware distribution attempt. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9986

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/award?keyword=introduction+to+computational+mathematics+xin+she+yang+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4424683/normal_6035beef32a0d.pdfIn PDF document text
    • http://kijekidajefi.getenjoyment.net/air_force_academy_head_football_coach_salary.pdfIn PDF document text
    • http://dizurexemubegog.mygamesonline.org/carry_on_baggage_weight_limit_klm.pdfIn PDF document text
    • http://ziposodepow.mywebcommunity.org/zaxozeliz.pdfIn PDF document text
    • http://mevukavotidu.getenjoyment.net/33315581525.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4454162/normal_600d4282dd7b5.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4389823/normal_5fc728dc0eec3.pdfIn PDF document text
    • http://sunakijabe.sportsontheweb.net/94841212489.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://814cba0f-f649-4223-bfe6-7884e6e02b9d.filesusr.com/ugd/c1108c_daf641f1078740be81870f6c6ccd026e.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/b2f32bfb-b603-4fe3-91ae-c85a6eef2683/74379788176.pdfIn PDF document text
    • https://s3.amazonaws.com/baritexovopa/application_format_for_college_tc.pdfIn PDF document text
    • https://6346cca1-8be9-442e-91e0-e35201572fa6.filesusr.com/ugd/a8c077_d96caff0973e4b748e8efa73b51b69e3.pdf?index=trueIn PDF document text
    • https://7ed754b6-a209-4558-9281-0032c7ee8ade.filesusr.com/ugd/4329d7_1f73ceb016d74e5eafa240c5f72d4789.pdf?index=trueIn PDF document text
    • https://6200e599-3f2f-4e3e-ab45-e6977ed7e777.filesusr.com/ugd/f8de3e_2acd17d16f1642ee99f11a70b7bc220f.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/tutapaxi/pobre_ana_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/taguxif/zojirushi_ns-tsc10_5-1_2-cup_micom_rice_cooker.pdfIn PDF document text
    • https://s3.amazonaws.com/bulikowexunepov/88341220686.pdfIn PDF document text
    • https://0cc2a7d0-6f33-4335-9ec9-554d9418487e.filesusr.com/ugd/cb4a18_334d0871b2da4a10862a3615c49f3c0a.pdf?index=trueIn PDF document text
    • http://zovawawopo.rf.gd/wefiwubijuzowameworezitut.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/17adef8b-d1e5-4fed-b974-b34397bfe09b/twas_the_night_before_christmas_book_with_pictures_online.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4c4509dc-aabb-4247-af40-f9bae8cb69a6/the_westing_game_book_plot.pdfIn PDF document text
    • https://s3.amazonaws.com/rurosaveruk/60961266001.pdfIn PDF document text
    • http://likefiradoweze.rf.gd/jevenipisewimox.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4cc56435-f82e-4949-bf29-f188efe0ade9/tarobixeja.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3c6bffa0-d8c4-4f60-9a3f-f0d03d2faaf4/inkscape_svg_converter_download.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001b2cf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1B2CF 5676 bytes
SHA-256: a077b867d886dc1475cd78f3cfa02e2e663f50e3db251c038fb573333979c2f9
font_01_sfnt_off0001c5f9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C5F9 12884 bytes
SHA-256: e63297d093d5f51724f68ff886289e898937d9281eac2928b44c5da85bda0cb3
font_02_sfnt_off0001f20f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1F20F 16776 bytes
SHA-256: e52337aa3b6f761b6270a4752f1816f30580aa6009e531d0c7b5e197d3fdb819