Malicious PDF — malware analysis report

Static analysis result for SHA-256 4dfe444b88bcf22a…

MALICIOUS

PDF

153.4 KB Created: 2021-04-10 02:53:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: aadf42fa83963a1913308943311b90c9 SHA-1: 9c4b27485747aa72e386bfb51ba9742dce14265d SHA-256: 4dfe444b88bcf22a7ee4f0f411fcd3ff65ef026c66199295d4875957522add74
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/strik?utm_term=westworld+season+3+episode+2+script PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4464315/normal_606e64350889a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4470689/normal_5fcc9dd387261.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4487618/normal_605dfa914ff62.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4473890/normal_5fe77cf4b5bc2.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4417528/normal_5fca96d407419.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/xalexojaxipud/lunch_invitation_template.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b4a3b125-a8f4-49e4-9acc-71560f50c821/67502641096.pdfIn PDF document text
    • https://46b09160-81f9-4cb3-9cca-f7b5b0c0229e.filesusr.com/ugd/179cc6_8d6b0549cfd34542995b6d47d6ef592f.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/41d821b9-ef09-46e6-9c25-8f4e36050540/how_to_connect_dymo_labelwriter_4xl.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/61729a6d-4238-47cd-b9ae-33f6f3cdf942/kenmore_elite_washing_machine_service.pdfIn PDF document text
    • https://s3.amazonaws.com/xefejevife/the_backyard_homestead.pdfIn PDF document text
    • https://d5bea983-5bca-41ba-aae6-6b688785cc77.filesusr.com/ugd/9ec29b_78a81e2c27464bc6bc6a70f6340ba054.pdf?index=trueIn PDF document text
    • https://cdd249b8-77b1-4a94-b024-8995efe4d959.filesusr.com/ugd/d394ff_0d4826e3f067402da35e22ea477bb58b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/3b527fe2-43b0-4f36-a032-7aef1ae49fe9/jamenajudaxorutakakefejo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ac7d444d-e51c-4aaa-ba7a-1f29fd1c12f1/vupixa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d85893fa-03a1-474c-b8f6-22c87f6146e4/vuwejusupoxoxepifudap.pdfIn PDF document text
    • http://ranuvukeguzekiz.epizy.com/6290761610.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/142eda1c-f14a-4e06-97ec-9ebda397741b/79361523826.pdfIn PDF document text
    • https://s3.amazonaws.com/dubiditiginowo/groups_of_animals_word_search_pro_answers.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d55ad8d1-16e6-4c2e-b648-02033d7609b3/tp-link_tl-sg1005d_v8.0.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e00c5ef5-02ae-4aed-a728-78979790aa5a/xemuzotibegevifi.pdfIn PDF document text
    • http://pitovevewapa.epizy.com/berhampur_university_syllabus_2018.pdfIn PDF document text
    • http://veboluzamusi.epizy.com/50463376193.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f1848f14-06c3-4f58-a804-8ddd71a39e9c/zufagode.pdfIn PDF document text
    • https://s3.amazonaws.com/dezajok/noholita_bikini_body_training_guide.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00020d41.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x20D41 5256 bytes
SHA-256: a0d2a299cd9da20f19305fd3e3f5913cb7a62b4d2ff423f48882a1c6b1f99269
font_01_sfnt_off00021f42.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x21F42 13048 bytes
SHA-256: 17f62333c4cccee993eefa8e6ba3a6c2255bf71ab6494c7bc2e090c6b75fedc2
font_02_sfnt_off00024947.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x24947 4324 bytes
SHA-256: 4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3