Malicious PDF — malware analysis report

Static analysis result for SHA-256 380b04959bcc6a37…

MALICIOUS

PDF

90.1 KB Created: 2021-03-11 04:33:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: b5f2a6e971053de3932c06e00fd2e7d8 SHA-1: 1709e0a92683ff67777feab01625f9770d810a63 SHA-256: 380b04959bcc6a372adf1099246b5d328d7b60cd0ae4ad70665f18aa312e29ef
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9951

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/123?utm_term=best+free+weight+lifting+apps+for+android PDF link annotation
    • https://piziwola.weebly.com/uploads/1/3/1/3/131382430/ripatimafonofu.pdfIn PDF document text
    • https://sagerogokijisoj.weebly.com/uploads/1/3/4/6/134601402/wizopiforenu.pdfIn PDF document text
    • https://tivuwamivubi.weebly.com/uploads/1/3/5/3/135384825/9370997.pdfIn PDF document text
    • http://fajamad.mypressonline.com/xafunububevi.pdfIn PDF document text
    • https://biteledazuxol.weebly.com/uploads/1/3/4/3/134315761/91560f.pdfIn PDF document text
    • https://gamidamivagug.weebly.com/uploads/1/3/5/3/135324690/kofotomizedidom.pdfIn PDF document text
    • http://wovuwukotuvoxi.mygamesonline.org/strength_training_exercises.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/1eb9a5af-29b1-41f2-9902-06c152289d55/lodibubosefu.pdfIn PDF document text
    • https://s3.amazonaws.com/xufaxoferugod/blender_3d_gratis_italiano.pdfIn PDF document text
    • https://s3.amazonaws.com/viregujipowuru/bike_rider_images_hd.pdfIn PDF document text
    • https://s3.amazonaws.com/sojebelevenex/smd_capacitor_size_guide.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9fd85579-6a6e-4f68-bf38-121b0eee97aa/resudetupafejeforopotu.pdfIn PDF document text
    • https://s3.amazonaws.com/kiwopusafize/16879409761.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/de97d7ba-09f5-4aab-934e-1bcb832e3adf/best_plugins_for_fl_studio_trap.pdfIn PDF document text
    • https://s3.amazonaws.com/gizonukorad/aluminium_sheet_plate_perth.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3322db4c-4255-474a-af94-cae5c33453d1/xufipoxojabujadevepewo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/685a2992-e755-4bdf-8425-e88258329642/7801902365.pdfIn PDF document text
    • https://s3.amazonaws.com/nodetuxapabara/82426915858.pdfIn PDF document text
    • https://s3.amazonaws.com/wovugi/petivababo.pdfIn PDF document text
    • https://s3.amazonaws.com/rozebofukixus/1058622235.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e14a5565-318b-46d1-a928-264b7c501dd8/xudowetogujekadowovi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/71920347-0ad1-453c-86f7-c7ee4833fb90/wing_chun_film_online.pdfIn PDF document text
    • https://s3.amazonaws.com/gumagabu/write_report_commentary.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/54b20621-8eae-415e-a22b-1537cd529055/7885943121.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/37af0b9e-6b5b-4a58-8345-bce16b351d86/what_colors_does_red_and_purple_make.pdfIn PDF document text
    • https://s3.amazonaws.com/varoximu/cell_stephen_king_full_movie.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/820a770f-9874-432d-98f3-6ccf4c9c74dd/dd_essentials_rulebook.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001107b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1107B 6440 bytes
SHA-256: 2ce5a7286efefc5aae27ce1c31b3347e159d00bd30cf97f509a0b7f7d49caffb
font_01_sfnt_off00012070.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12070 5444 bytes
SHA-256: 1bba69939ed10ad092b5018f1e8a93eee700b748acd7d023ad9681f4ab97a53f
font_02_sfnt_off00013309.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13309 11480 bytes
SHA-256: a8c69a4aa64f54a7f6d2511923f4899b7c65811263cbdbabb852b23bce1f8c62