Malicious PDF — malware analysis report

Static analysis result for SHA-256 36a7e97c5aef8688…

MALICIOUS

PDF

75.6 KB Created: 2021-03-20 18:53:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: d0b34a4e13208d98a5dea5472e26c851 SHA-1: df333eca9e6ef069912c2a2721c34c9ddcb16cd7 SHA-256: 36a7e97c5aef86884daab6082abe77aca8dd364a5c0cd13f9bf6211affa9f08a
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/123?utm_term=finding+slope+intercept+form+perpendicular+line PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4501383/normal_601a7793afe24.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4473031/normal_603f51138065b.pdfIn PDF document text
    • https://xavexipaw.weebly.com/uploads/1/3/1/6/131636683/raruf-lotopese-sobop-fibalujeletusis.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4490141/normal_603c4809297f1.pdfIn PDF document text
    • https://denapifikuzo.weebly.com/uploads/1/3/4/6/134634031/7541726.pdfIn PDF document text
    • https://vusuranozaxo.weebly.com/uploads/1/3/4/0/134012668/renafajesud_zejewufajajuw_vomiradabaj_faxawamebaf.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/3c1faee2-9bf7-4057-91b5-b05257da97d6/18547913742.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b5d421e6-f34d-4e29-a1eb-5a93c911314d/mimejegopiw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d759e21b-0d2e-49bf-bf60-251c587356b0/how_much_is_samsung_s9_in_nigeria_now.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b9f61d42-0572-4dca-9536-470ba0aecbda/what_is_a_sense_of_unity_definition.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/16790339-0a5d-4b1e-88a1-39bdcc7cd36b/in_china_the_month_of_chrysanthemum_refers_to.pdfIn PDF document text
    • https://1c684d3d-b1aa-4d58-8f8e-408f9cf37fac.filesusr.com/ugd/64d889_4fee2dfae52a4b1393ea2533caf863ab.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/460ed793-513f-4cd8-8bf8-43bcbab494d6/software_development_engineer_in_test_resume.pdfIn PDF document text
    • https://s3.amazonaws.com/golepe/7037253994.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aec850ae-ffce-407b-86e9-01288f9d7e99/zosenoritejuxutafi.pdfIn PDF document text
    • https://s3.amazonaws.com/wujodibu/meloxububokakasemonosi.pdfIn PDF document text
    • https://2aa89031-56ac-4de1-b828-aabe99840ec8.filesusr.com/ugd/cf14a4_d5c8158f16844aaf9d44b82fb4b160e8.pdf?index=trueIn PDF document text
    • https://78fa80b2-8629-447b-ad63-53e91e8d4948.filesusr.com/ugd/8f02de_6f3c3b4975c54203822213ddf291ed52.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/1a5c5dbb-76b5-4740-b9ff-6f4564538b74/matlab_plot_subplot_tight.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aeef73ae-7b1c-40d4-b1f7-cb90eabac4e6/dafajumuvi.pdfIn PDF document text
    • https://b5d51143-f34a-4a4f-9265-6917490cb775.filesusr.com/ugd/9f69bd_ae6949316e384d1abe2b92397815551a.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/c666c86d-9d0c-4f7e-964e-9529477375e4/40926842155.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e7e2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE7E2 5432 bytes
SHA-256: c4b6369b6b5690403fb45d6b95d23b7743605b7920a2192cfc43275656b78982
font_01_sfnt_off0000fa4d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFA4D 11148 bytes
SHA-256: dd8d14916ec33476f42c225670ead5ea9aca0c2043ab6596903f173767b9f45a