Malicious PDF — malware analysis report

Static analysis result for SHA-256 51fca433f3c37ab3…

MALICIOUS

PDF

81.6 KB Created: 2021-03-08 21:25:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: f947821c6bb2ffa79ee62766107206f7 SHA-1: 1ceb4665e685dc4970e7ba95dd53b2c7624a3cc1 SHA-256: 51fca433f3c37ab3db3bc0cc14a47e78e8c00a9acfcf83f3e61e7cec30917413
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=pokemon+mega+power+cheats+pokemon PDF link annotation
    • https://cdn.sqhk.co/letareximo/jiQ7Djg/rusewanofazadubo.pdfIn PDF document text
    • http://dommasters.site/60033859487ky0nq.pdfIn PDF document text
    • https://cdn.sqhk.co/nowonipewo/iirhgZl/99584336262.pdfIn PDF document text
    • http://ver-alex.website/tukorusajakezadoruvokuzjbnyj.pdfIn PDF document text
    • http://lnstagramcopyrightcenter.com/garmin_gpsmap_64st_gps_reviewuiyar.pdfIn PDF document text
    • https://cdn.sqhk.co/furugilenu/uXOWjc1/legoland_pick_a_brick_wall.pdfIn PDF document text
    • http://lovemecompletely.com/international_business_master_degree_onlinenn0vf.pdfIn PDF document text
    • http://soinjaga.ru/fesigedodexelodakafobo5419g.pdfIn PDF document text
    • https://cdn.sqhk.co/kezagajasiw/geohijg/javisebodovikiwipoxerek.pdfIn PDF document text
    • https://cdn.sqhk.co/dipujabuxiw/ifqIi1s/lelekipamiwonamixona.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/7f816de8-a1a6-43fe-b9b4-8836e062755f/panasonic_tv_red_light_flashing_2_times.pdfIn PDF document text
    • https://01dc7cc6-b8ed-446e-8cc8-1ad78882ed38.filesusr.com/ugd/e23fbb_a6af3042402a4a9f86c7a4609fc6aa6a.pdf?index=trueIn PDF document text
    • https://5be7aec3-7d66-433b-ae1d-2bfb807ddf2a.filesusr.com/ugd/24deb6_42d09ee9721c4e7f86bcdc7f1967d184.pdf?index=trueIn PDF document text
    • https://0b609444-e5a2-4a7e-9779-a3c6bae51a53.filesusr.com/ugd/529dbf_64de25672f6c4d1382a2f04622c1a5de.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/e91b1196-e499-4241-b212-c02f296d1324/the_canterville_ghost_summary_chapter_5.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a331d127-9a5f-43cf-af4a-1eecdb8233ab/sesuketalisejoluta.pdfIn PDF document text
    • https://d67926d6-99fe-48a4-938f-95006fdf2de6.filesusr.com/ugd/21d82e_da434095fa3b4c32b771424a6995e5db.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/9fc6b9ff-5506-4892-83be-bd8c61d490d7/harry_potter_book_2_chapter_7_quiz.pdfIn PDF document text
    • https://f74ea38a-ab8d-49a0-8d31-9a1d7ce64423.filesusr.com/ugd/5ceade_e8f82df9aa0c475bb94dd3c7de8a532f.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/19cbc207-3ff2-4947-bbfc-a261f9881678/what_is_heat_of_fusion.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/16fb374a-779d-4860-999e-496ed0f2d55d/97625136980.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/08f31523-8ba3-433e-b2e3-c5ee41ef2bb7/9282765641.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fdd1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFDD1 5472 bytes
SHA-256: 4325f29c22e97809464c2ba66f0e9bfb4d36ad2a1f8d06a2716bea996abe67d0
font_01_sfnt_off0001105a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1105A 12712 bytes
SHA-256: 7666e9b2bcfdca6c119aa7b0fd6142fa53ed0bab4c07402bf44fdd69118cc5a4