Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa3fa895e424274c…

MALICIOUS

PDF

77.1 KB Created: 2021-05-24 12:43:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-20
MD5: ca0c4374feffc08aa13b5d1503b4417d SHA-1: c31ea7302a9b236c700097023487646be42a1243 SHA-256: fa3fa895e424274c9bb74d68139710a374684e041698233639dfa49a07ba5523
204 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1204.002 Malicious Link

This PDF file was detected as malicious by ClamAV and an ML classifier. It contains a link farm and a redirector URL, specifically https://mezovuduw.ru/strik?utm_term=american+dad+apocalypse+soon+mod+apk+1.2.12, which is presented as a download lure. The document body, though heavily obfuscated, suggests a lure related to software downloads. The presence of multiple external links, including one pointing to a PDF on AWS, indicates a potential attempt to distribute further malicious content or engage in SEO manipulation for phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/strik?utm_term=american+dad+apocalypse+soon+mod+apk+1.2.12 PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4377410/normal_6027a19557897.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4428341/normal_6057e0d84552c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4420030/normal_6000e4ea09dcc.pdfIn PDF document text
    • https://gomamuna.weebly.com/uploads/1/3/5/3/135304292/vikamo-wukidazir.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4383308/normal_6017d42d77733.pdfIn PDF document text
    • https://dawasaga.weebly.com/uploads/1/3/0/9/130969366/7488832.pdfIn PDF document text
    • https://daliroxemonove.weebly.com/uploads/1/3/0/7/130775241/xavujebokurefe_zumewapo_womozogi_suxuvu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/vovuzize/jutuxidosatezoluxufam.pdfIn PDF document text
    • https://s3.amazonaws.com/lorerexeg/15539535555.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cae8868c-2295-4e21-ae2b-757d17347e2e/15464120161.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/258fb457-f8f6-4bdc-9d1e-20de61a8c118/how_to_set_time_on_tissot_touch.pdfIn PDF document text
    • https://s3.amazonaws.com/fovezewi/bhojpuri_bhakti_song_2019.pdfIn PDF document text
    • https://s3.amazonaws.com/timituvupame/the_girl_with_the_dragon_tattoo_2009_amazon_prime.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7e613c45-33bf-4033-ad53-37c64767360e/11785542627.pdfIn PDF document text
    • https://s3.amazonaws.com/bugutaj/4843628216.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a0589a3b-1696-41fc-b36e-294f9ac4f144/difference_between_reference_and_pointer_type_in_c.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/46f1ba2e-b0fb-43be-b9a5-183801d16503/26090689732.pdfIn PDF document text
    • https://s3.amazonaws.com/bewibiwat/what_chapter_has_the_most_verses_in_the_bible.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a3a6f191-cd88-4b69-a875-815aff316a2c/serul.pdfIn PDF document text
    • https://s3.amazonaws.com/lebaxa/46516762897.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e661aebf-86f1-478a-a9f2-63a02fb1626e/is_there_a_free_willy_4.pdfIn PDF document text
    • https://s3.amazonaws.com/kovibu/wilop.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef7d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF7D 5588 bytes
SHA-256: 55fa6618bcd6e43babd5e1b6b1a7a97fa6880548c5e6d15b8e71a04c5b5e5c33
font_01_sfnt_off0001027d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1027D 10632 bytes
SHA-256: c14cf351d7a982300a16e13c9adc5fee085b4729426a2157380c716ec3a5dcea