Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa3485f3b87a0e35…

MALICIOUS

PDF

93.1 KB Created: 2021-03-15 01:09:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-26
MD5: 7d881c61b7c6d446aaa97ae44f05b00d SHA-1: dd2bece42576319190c6d482798ba2865c01c799 SHA-256: fa3485f3b87a0e355951aa92355ea9c03211d72ec86a3f8e0ad157c59e80508e
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The file is identified as malicious by ClamAV and an ML classifier, and it contains a significant number of external links, many hosted on disposable platforms. The PDF_SEO_LINK_FARM and PDF_SEO_DISPOSABLE_LINK_FARM heuristics indicate a deliberate attempt to create a link farm. The primary external URL, https://lozipotod.ru/wix?keyword=theta+phi+alpha+kappa, suggests a potential SEO manipulation or phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/wix?keyword=theta+phi+alpha+kappa PDF link annotation
    • http://gatorama.site/what_is_the_average_monthly_household_incomeheoq8.pdfIn PDF document text
    • https://cdn.sqhk.co/nodujugebi/gdRDWid/gelomifobi.pdfIn PDF document text
    • https://cdn.sqhk.co/rubovadu/hbjdfOB/56266911239.pdfIn PDF document text
    • http://cashfree.store/what_does_222_means_spiritually0mvl8.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://923a8ca3-316b-4844-b38f-9bc955ad4852.filesusr.com/ugd/312e0e_5997be00416a4f68a2688e445547e641.pdf?index=trueIn PDF document text
    • https://44407f20-7244-4107-9544-84d8151b6f9a.filesusr.com/ugd/8508de_0dbd2635ab094ac999ef2f8566f71a8a.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/6913524a-50f6-41e2-af9d-8586b3a725ed/jaxub.pdfIn PDF document text
    • https://c788b29d-df2d-4d46-9946-349e8cce89b7.filesusr.com/ugd/a9e086_c4d6e67c91414106916af71249568fc2.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/4c655260-63ff-470b-ba5d-1bca1ddd1021/how_to_change_audio_output_samsung_tv.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fee86fb1-ab0a-4245-80c7-1da76076843a/40315817725.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e5f3e30b-e45c-4625-a074-a20f44441fde/rupipowadatunugi.pdfIn PDF document text
    • https://s3.amazonaws.com/bexolamabad/getenuvikekukexesobej.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/08637a4f-b4fa-4a18-b3e8-7fc0a4da6681/toro_power_clear_721_e_spark_plug.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dadfe4c8-efc4-4804-81c8-72ceeee5d14c/30245474283.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d0df958f-0a6d-4cd8-b853-1a3ac3f64197/25426963640.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ad5ca77d-1598-4c4d-8402-1ff16c3839cd/rapaxugawozovemuwa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3dbde80c-f96a-4963-8e9a-a01a12c70e3e/vobebugofoja.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/60a1e635-02d1-4481-8a07-e10b191dc25b/30782563571.pdfIn PDF document text
    • https://s3.amazonaws.com/nutanigonu/bumonemewaser.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012fb8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12FB8 4644 bytes
SHA-256: b4d2f56b1c2ec93d710ddb08731dbec08fbee790f5ab435a4b22c58f6f043437
font_01_sfnt_off00013f82.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13F82 11484 bytes
SHA-256: 83fc6cce78a6e61893f4e2e50783864df7f558a509b79d8548c97825978a494d