Malicious PDF — malware analysis report

Static analysis result for SHA-256 29659d83ff66bed6…

MALICIOUS

PDF

76.9 KB Created: 2021-03-30 22:38:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 3ae523d400f012c9df46370c42fba263 SHA-1: aee8ea3ee398b29aa4766b895c239040706f538b SHA-256: 29659d83ff66bed60e557143eddbe37076d7b6da257cf22af2465b6ddd36b1b5
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fokemale.ru/wix?keyword=free+prank+calls+to+friends PDF link annotation
    • https://metumarexidema.weebly.com/uploads/1/3/4/5/134591821/ee87e03bb2c3.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4455174/normal_5ffabfad7b4af.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4402949/normal_601d24bd0a38a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4495264/normal_5fff6b7ee2145.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375352/normal_606376c105fb1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4387408/normal_6054b546b2ede.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4388062/normal_5fe141954b286.pdfIn PDF document text
    • https://rigefenasoje.weebly.com/uploads/1/3/0/7/130776330/bawisafesafenus-buxujufufopir.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4423454/normal_60380d2abeafc.pdfIn PDF document text
    • https://mevavenepid.weebly.com/uploads/1/3/1/6/131637679/6644017.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4382614/normal_5fcd3d87d2299.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4413838/normal_5ff1c08655a1c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://aca56392-15ae-48e8-982c-fdf6c4ac0dc3.filesusr.com/ugd/00c070_eac7ae9f5e664b338faa3edef22ab75b.pdf?index=trueIn PDF document text
    • https://667b589a-70dd-4c78-a03f-47f6e9f07b1f.filesusr.com/ugd/db80c5_f577f82eefad4c48a2dfe93b497c89b8.pdf?index=trueIn PDF document text
    • https://84d51d8d-5932-465a-b044-5d36dace581c.filesusr.com/ugd/98e2de_2cd04957157e43fabfef06ebc9fe5c55.pdf?index=trueIn PDF document text
    • https://ba9dc33f-61c2-415e-8598-c57272458a21.filesusr.com/ugd/c05727_35896bb89f8a453c970b83d15487ac92.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/3d170243-e11e-4d56-b696-f8ce27edabb2/kadadozemalanewejimeto.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8d09f14e-83ef-4dfd-a7f2-e7b7781cc757/strikemaster_40v_ice_auger_blades.pdfIn PDF document text
    • https://367e539a-c541-4439-991c-4bf2bef2aa7a.filesusr.com/ugd/77d535_742bb5129fba419cb422a6fbbd7dd08a.pdf?index=trueIn PDF document text
    • https://f18b8dc1-3ce9-44bd-8712-01435d039869.filesusr.com/ugd/b97cba_c5ce4d93351d442d8722a56b1ae5fca6.pdf?index=trueIn PDF document text
    • https://7fe1f042-206b-4735-a408-f56337efeeb4.filesusr.com/ugd/d34b51_6c7d2ab98de74760a9462f2110114456.pdf?index=trueIn PDF document text
    • https://bef89f6e-6323-4b84-ad9d-a44490bfcc4f.filesusr.com/ugd/96768c_14a9af574d534594ad684b6566c9612b.pdf?index=trueIn PDF document text
    • https://2e81f42f-67f9-46a9-89e2-a5f3ab3b03ee.filesusr.com/ugd/f138f5_1e90930eab5d40a2aceb0b27916964b4.pdf?index=trueIn PDF document text
    • https://f3c4034a-4a94-4c47-b6c5-0445626d7bf8.filesusr.com/ugd/655f09_72c2f6055b0e4647abfaf1bbd317b84b.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed5f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED5F 5168 bytes
SHA-256: 9630543d1c77346714ae8883166372858ddcf452d28846400c946e1fa2e77fd2
font_01_sfnt_off0000ff0a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF0A 11524 bytes
SHA-256: 001dd855b2a06d8aab4bcbc341c06171cd85feec3c5f8c9b6f6553a5b6e42de7