Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c7223b0eb574ab9…

MALICIOUS

PDF

90.5 KB Created: 2021-05-01 06:30:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: fe13336760491bd79604830db3460118 SHA-1: 204d2342fc6392abcbc1c2d3dff15d822c0c29cd SHA-256: 5c7223b0eb574ab91c7801afa2670a2205666f4c6e6842a818b63dccdfd6565a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fokemale.ru/strik?utm_term=how+to+do+code+freeze+frame+on+imovie PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4503309/normal_606e9aaeda8a7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4389570/normal_600b454fa7637.pdfIn PDF document text
    • https://cdn.sqhk.co/jaxubefe/iegiDib/ninja_air_fryer_xl_manual.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455376/normal_6058d73d3f1cb.pdfIn PDF document text
    • https://ruzamugube.weebly.com/uploads/1/3/4/0/134040566/lepatojadila.pdfIn PDF document text
    • https://cdn.sqhk.co/zadoweferoxe/hiicje2/hero_rescue_mission.pdfIn PDF document text
    • https://wosubazaroden.weebly.com/uploads/1/3/0/8/130813518/siwovedakiral_pexarenuxorigu_xodabuxigog_zofadut.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4415754/normal_5fdc55ae7bb15.pdfIn PDF document text
    • https://gakatonigi.weebly.com/uploads/1/3/2/6/132681340/vesezupinon.pdfIn PDF document text
    • https://cdn.sqhk.co/metusoteliza/ehjkjif/smart_balance_butter_spread_nutrition_facts.pdfIn PDF document text
    • https://cdn.sqhk.co/zaliroded/iIrotja/last_survivor_last_runner.pdfIn PDF document text
    • https://cdn.sqhk.co/fudikuzi/jtojjje/h_m_rolling_stones_t_shirt.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/cc90d0cf-a5ff-4de3-b2b5-debd63b227b3/39621419170.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/641b49ee-69e8-4f35-a79f-3419df538f3f/sotiligaretonemepupuf.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a023fdf-7a7f-4530-a618-cabad5acc7c9/duwizaliw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/df360222-247b-490d-a922-c9f10ac1b514/south_carolina_drivers_manual_audiobook.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/51a9da43-9d81-4ca0-86d2-10047e937223/does_murano_have_transmission_problems.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/880e46cd-1328-450d-9a45-f90e228eb43e/larupekuxixemepimu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/369ba858-3f04-490c-8465-457672554d0f/2297258875.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1b3fae70-e547-4022-b2c1-323631d5fbdf/sexual_reproduction_definition_easy.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8f30091e-9942-4692-95eb-f196c8a49c16/revemo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e22e062a-177a-40a6-a44d-a226330fc771/the_reason_why_is_that_or_because.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8327590a-e306-4a3a-8415-d3c0eecced51/kazizejejeviwitumibanepap.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fa476d7e-400e-470c-85bc-75273093576b/68068911212.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000124de.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x124DE 5120 bytes
SHA-256: 2817ea270c50016bbe398c970974a785d0c7733247144f6c5e8d0449d8fe0c1c
font_01_sfnt_off00013652.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13652 11048 bytes
SHA-256: 31231629a1dbef76dec8463c99db1554eb95488fec01c52ff1d49b397c102d5a