Malicious PDF — malware analysis report

Static analysis result for SHA-256 281b4176894963aa…

MALICIOUS

PDF

79.7 KB Created: 2021-03-24 16:20:36 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-13
MD5: 621635baa680100e2c3f015b31cc2753 SHA-1: 1ddf7ece9dd314ef9d072d5c7615f327097ed990 SHA-256: 281b4176894963aabe255ee7f2be2a83e156f607d7e666c873e8f073f36b222c
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics as a link farm and by a machine learning classifier as malicious. It contains a significant number of external URIs, many pointing to disposable hosting, indicating a likely SEO spam or phishing campaign. The ClamAV detection as 'Pdf.Phishing.Trojan' further supports a malicious intent, likely to redirect users to phishing or malware distribution sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=aquasource+faucet+valve PDF link annotation
    • http://zawugexoj.22web.org/lesixitojowobadedip.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4401714/normal_5ffdb0baba485.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4501775/normal_60055a78e8f53.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374979/normal_60517e625ecb3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4421224/normal_603f7d587ea84.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4389797/normal_5fd5f70e155d5.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://lagadasisipas.rf.gd/pulupenemoziwixekigatore.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/245a6143-e5c1-49f2-bfbf-a1fddb5e48a4/how_much_horsepower_does_a_2016_mustang_5.0_have.pdfIn PDF document text
    • https://0e733887-fd72-4d21-8b10-0a39cafbc931.filesusr.com/ugd/1e4d10_cc76babab04d4467897325283a3782f8.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/253f29dd-3ef9-4c3d-92a0-4fe1b079ba9a/70878791865.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9db9096c-27bc-4ccf-8f33-72db8cda4aca/the_lord_of_the_rings_3-book_clothbound_special_editions.pdfIn PDF document text
    • https://07e0a16e-b77d-475b-b724-88bbaedb347c.filesusr.com/ugd/8e9e2f_20ea22e3bfbd405bb9afd7e1dd4a04be.pdf?index=trueIn PDF document text
    • https://29ce6865-365c-47c4-9f0a-635d6f965865.filesusr.com/ugd/0d6b77_ad7545755a4a4eb2b4075af19de0bd19.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/1e806817-9d0f-49df-bcfa-aad35eda2bff/learn_python_for_competitive_programming.pdfIn PDF document text
    • https://ce322291-b3da-4cc2-ae0f-523e25daec44.filesusr.com/ugd/4530da_0e17e8244db9416abebc876a6f11d0b1.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/7c7f9546-d628-4fd9-976a-88e1ebf5d610/prince_charles_net_worth_2019_forbes.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dc5ce331-4247-4e98-8155-52a6f5146d93/kelev.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8ce369a9-0994-44f9-a839-524c341cfa46/escape_from_mr._lemoncellos_library_show.pdfIn PDF document text
    • http://kiwasebax.epizy.com/harry_potter_movies_with_subtitles.pdfIn PDF document text
    • http://jejivosijej.rf.gd/ragezozezifapasa.pdfIn PDF document text
    • https://6d428a25-da86-44fa-8f13-5b0f09742281.filesusr.com/ugd/3649d2_f1c8294ea59047e297d2ba0fb93bf836.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/7d2c2ab6-fa2f-4c62-b9f7-9670b2c310a5/54153304645.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6630cb9d-4e08-44c3-af9c-720c2587ec1c/cmo_hacer_un_manual_de_procedimientos_en_word.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb80.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFB80 5052 bytes
SHA-256: f92a96a6a5a89a2facb703b845dcbf8d3035d2d6f0a9276927035a86f28715d2
font_01_sfnt_off00010ccc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10CCC 10748 bytes
SHA-256: 5cff8ce177d54b6e4fc377df2b166c9a16ddb11b5cf58e316e2c663600c6bb51