Malicious PDF — malware analysis report

Static analysis result for SHA-256 f446fc7b5f9d0bfb…

MALICIOUS

PDF

75.4 KB Created: 2021-03-14 05:10:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-02
MD5: 4067ba3826fa45a5f0fc70c9155bf551 SHA-1: e9257e31d2c178ebd3aabee74f866ba33b15013a SHA-256: f446fc7b5f9d0bfbd1d443183483f5735cd2a14578d647dc17b7ca27ae0aa582
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics, including a critical ClamAV detection and an ML classifier, indicating malicious intent. It contains numerous embedded URLs, with at least one pointing to a suspicious domain ('jumiwimov.ru') that is likely used to host malicious content or phishing pages. The PDF structure and embedded links suggest it is part of a link farm designed to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=aquasource+faucet+aerator+removal PDF link annotation
    • http://watogoda.mypressonline.com/english_test_beginner_100_questions.pdfIn PDF document text
    • https://cdn.sqhk.co/pudinivil/ojd2Chh/gatujejopemuxaluzupikupel.pdfIn PDF document text
    • https://cdn.sqhk.co/roretuduva/2gcjagf/earthnow_bill_gates.pdfIn PDF document text
    • http://foselosen.sportsontheweb.net/nutrient_agar_oxoid.pdfIn PDF document text
    • https://cdn.sqhk.co/murerezusa/aX9f4vT/xazufo.pdfIn PDF document text
    • http://kimujedat.mygamesonline.org/how_to_work_to_stop_human_trafficking.pdfIn PDF document text
    • https://cdn.sqhk.co/dejuxafe/gjBw9jf/fobifuvimapibanevovu.pdfIn PDF document text
    • https://cdn.sqhk.co/retepisej/7mH8him/54792013933.pdfIn PDF document text
    • http://janafan.scienceontheweb.net/7803945418.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://bujekotu.atwebpages.com/2005_buick_lacrosse_cxl_transmission_problems.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/39b3d278-3027-411d-a016-74faec7eb692/19664664223.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/db1cf221-efa8-4ed1-9879-1fa706cb6d84/is_there_a_difference_between_sae_30_and_10w30.pdfIn PDF document text
    • https://s3.amazonaws.com/vunizi/baxuj.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8b929d67-dab3-4910-8b4b-1b1077722230/4th_grade_math_worksheets_word_problems.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/abeda9ca-fd0d-4f92-bd34-16c6d538c29a/mepowa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f55637b9-565b-4b72-879e-81c1f5136320/bewadubur.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e5b7a8d9-0f42-4e97-8d02-8bf853a67c2c/mississippi_drivers_license_status.pdfIn PDF document text
    • http://vunonam.atwebpages.com/barumobiwisejajopur.pdfIn PDF document text
    • https://s3.amazonaws.com/viromibukoleliw/58796567570.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4b782dbb-bc9a-4f24-89f2-da5ac84a68cb/super_mario_bros_2_nes_cheats.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2490512d-f6cf-4703-8ef9-5f1d6603b893/samsung_m2070w_wireless_connection.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fb45adbc-a285-4af1-857c-31c6516dc27f/how_to_do_aa_meetings_on_zoom.pdfIn PDF document text
    • https://s3.amazonaws.com/jusagi/naneb.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/043ea791-d689-4675-b3d8-eabaff222389/50773197749.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ecfe.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xECFE 5200 bytes
SHA-256: 1dfb0ce55f90824565fd993de3c273e37d96051c855c6957b04c45819e367c5f
font_01_sfnt_off0000fea3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFEA3 9900 bytes
SHA-256: ec80c2b38b653a17daaac5253d00559ecd070fe4672854145e03c77730350833