Malicious PDF — malware analysis report

Static analysis result for SHA-256 6457a329dcccf58e…

MALICIOUS

PDF

90.4 KB Created: 2021-03-31 15:41:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 9235972f15ab1abefbe3beb221716354 SHA-1: c30123d78f146334394c4c30d799652aa5df58fb SHA-256: 6457a329dcccf58e13ae2a5aeec51576ee16600ee90b0d6251ef5d91ecc4f60a
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9952

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/wix?keyword=great+writing+4+pdf PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4379476/normal_5fca2a99337d6.pdfIn PDF document text
    • https://cdn.sqhk.co/zewesifadeka/O6jj9ic/27246181264.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375690/normal_600cb7419220d.pdfIn PDF document text
    • http://hangookoil.ru/vmware_for_windows_free0gbsg.pdfIn PDF document text
    • https://cdn.sqhk.co/zatovafer/R0DhfjA/spotlight_x_room_escape_level_7.pdfIn PDF document text
    • http://delifeschool.com/zetebirodt1g.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369657/normal_603fa9e22b00d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393485/normal_5fd85be0d1305.pdfIn PDF document text
    • http://dfahsdfgjsfg.online/53061383588xizzg.pdfIn PDF document text
    • https://cdn.sqhk.co/voduzetefir/iijjeII/zetefovapaluzadirekifek.pdfIn PDF document text
    • http://powerpoint4you.ru/40980787548evp58.pdfIn PDF document text
    • http://islandlandscapesbb.com/wedding_anniversary_cards_for_freek2vfp.pdfIn PDF document text
    • http://leoidet.xyz/phantompdf_express_downloadaqzz1.pdfIn PDF document text
    • http://shop-onlinediscount.xyz/vexopby7nq.pdfIn PDF document text
    • http://fruitslope.online/world_of_darkness_atlantisae3u9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4475989/normal_6036fd32dfc29.pdfIn PDF document text
    • http://lnstgramhelpcopyright.com/how_to_cook_pork_ribs_in_power_pressure_cooker_xllfuao.pdfIn PDF document text
    • https://cdn.sqhk.co/wivusaranonu/1ajjggb/72985531024.pdfIn PDF document text
    • http://tacfitproducts.com/burushaski_grammarrl9xc.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://87164119-88a6-4d6d-a72f-b109cf2d88b9.filesusr.com/ugd/bd0a66_bcbd9051d5c84389a163e7a75b4194d4.pdf?index=trueIn PDF document text
    • https://0dc5016f-38c0-4e11-84f4-4717e3ef4ec7.filesusr.com/ugd/4fd84c_8268ef814a43456c9a4ada5891d9dd12.pdf?index=trueIn PDF document text
    • https://c482eaa1-e3aa-4fde-9473-53ba98cc9791.filesusr.com/ugd/94322e_d7c68b3bb9e44d7e9337321f511d850a.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/891c88e3-5274-4642-8703-86411aa2cb09/58991747737.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/116ae512-e974-4202-91cb-ab5f0cfd932a/verizon_remote_codes_for_tcl_tv.pdfIn PDF document text
    • https://42cc6f6d-9125-48bc-bce4-1bf15f49b1be.filesusr.com/ugd/7c30af_3710d918b9d24b088e80c97c2985129a.pdf?index=trueIn PDF document text
    • https://4adff18d-dc39-4349-be2c-eeb12737f1cb.filesusr.com/ugd/9117e0_e52ed991cadd41a09b4ba06c90138819.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f93b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF93B 13268 bytes
SHA-256: 78586bcaf0e21ba332a983affe852791ea5fe9a9b641cb82c4872bfb33a051cc
font_01_sfnt_off0001240b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1240B 5212 bytes
SHA-256: 3d27d8ee093bb5b35cd933483e9c61cb2c7acee76793ecee9e0811d10c002810
font_02_sfnt_off000135f5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x135F5 10932 bytes
SHA-256: 58233da5f5854c9f8e3a91e5e657d1b6aa420ba07f1fcf2560ce25ac0d3a096f