Malicious PDF — malware analysis report

Static analysis result for SHA-256 4964515535e3d802…

MALICIOUS

PDF

81.0 KB Created: 2021-04-13 05:13:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: fbd6fe8a41dcd87594247f1f9221bea3 SHA-1: 70d74a1c5c877de8e22967fa0328bd902412b19a SHA-256: 4964515535e3d80215b7523ff145164e5f07e2a3484b65dea8cd8fa5ef5cec3b
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8277

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/strik?utm_term=hunger+games+mockingjay+part+1+end+credits+song PDF link annotation
    • http://iciko.xyz/kowosoretuvosawipljax9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412592/normal_606712ef2e7c2.pdfIn PDF document text
    • http://leomannapov.com/948420636450ndwh.pdfIn PDF document text
    • http://m-ryanaf.site/1994_honda_accord_engine_swapb8vjd.pdfIn PDF document text
    • http://hermidkovo.info/sevewiziripuzotoxozafx10.pdfIn PDF document text
    • http://medicalpracticementor.com/sezolezitudi8t1cv.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4410415/normal_605abbe9427b1.pdfIn PDF document text
    • http://poopo.ru/army_height_and_weight_standardswtn7m.pdfIn PDF document text
    • http://potozafit.medianewsonline.com/pidutenanu.pdfIn PDF document text
    • http://about-central.com/75313527200lulb7.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4469638/normal_5fe2bc087b45b.pdfIn PDF document text
    • http://fuxutigox.mypressonline.com/vivapanegazotaxugubagaxu.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4381752/normal_5ffb75d534872.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374859/normal_6016b6cbab734.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://59bb578d-b312-442a-858b-1a1a54b18a6c.filesusr.com/ugd/c79b1c_c90cd978554f40fe8d8bb83d9985f9a7.pdf?index=trueIn PDF document text
    • https://b2fc43c4-60ab-4dc1-a1c8-84833fda4e2a.filesusr.com/ugd/37321e_03c7923843ae48c289ccafa56e8a0162.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/704e33cb-638d-4768-be1c-9ad93f79c89a/31628256039.pdfIn PDF document text
    • https://edefa294-c65c-46c5-840b-8a4669b9fdfe.filesusr.com/ugd/e4a001_03691b0cfae14608a3e39fce455c61b5.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/fb3f308c-11f9-43c9-81f8-2e07d6ffef69/wavox.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5117c158-578f-4b38-80bd-481867a3174c/79820268661.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5788ef3a-3292-48a1-8cf3-587f4df528bd/soundarya_lahari_slokas_tamil.pdfIn PDF document text
    • https://59548cc9-d6a6-4b2e-bd73-2bfb7290c7b5.filesusr.com/ugd/3fd21f_5e218db14c4d4dfcb264cd7a77287871.pdf?index=trueIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011056.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11056 5616 bytes
SHA-256: 71b20a7fb06b4ae5505424c1140b57670355ef1d263f3054aeafc354d4fd0de1
font_01_sfnt_off00012378.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12378 12072 bytes
SHA-256: ac5d576d358b4f343e540b8d842819532b0c97fc7e0bae190a72dfe351029c65