Malicious PDF — malware analysis report

Static analysis result for SHA-256 646eea2e365c6579…

MALICIOUS

PDF

77.3 KB Created: 2021-04-26 09:16:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: b6b4351c1779f2493955e5caf4ed5188 SHA-1: 9503c728f45d961b645921384d16c884eaf2519f SHA-256: 646eea2e365c65792a8f19f2498b3de053549aa7061ae4e0531ced3962e84375
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/strik?utm_term=miller+syncrowave+250+dx+high+frequency+not+working PDF link annotation
    • http://inostrana.com/resumen_del_cuento_borges_y_yobvrbx.pdfIn PDF document text
    • http://zenajok.medianewsonline.com/antenatal_visits.pdfIn PDF document text
    • http://smirno.life/brunswick_marine_emea_com9dz05.pdfIn PDF document text
    • http://xumupizaxuto.scienceontheweb.net/23356376392.pdfIn PDF document text
    • http://takipleskazan.org/7789275469627ua4.pdfIn PDF document text
    • http://gloslides.com/karuppasamy_kuthagaikarar_full_movie_tamilrockersiiivk.pdfIn PDF document text
    • https://zerorobasajegi.weebly.com/uploads/1/3/4/7/134751736/kujomuxuwefomo.pdfIn PDF document text
    • https://gifapaneg.weebly.com/uploads/1/3/4/3/134368366/f28ca2e94.pdfIn PDF document text
    • http://labifovejes.mypressonline.com/86156100489.pdfIn PDF document text
    • https://xewidepomizexas.weebly.com/uploads/1/3/0/7/130775014/rewusatodoka.pdfIn PDF document text
    • http://nosinoski.shop/sofewumezagadelipijugs08g.pdfIn PDF document text
    • http://mantenancie.com/is_vegetables_healthier_than_fruitiwqjq.pdfIn PDF document text
    • https://lasuresupaka.weebly.com/uploads/1/3/2/6/132683400/kitijamenabe-lukagowosage-tipugaruj.pdfIn PDF document text
    • https://lefitujeledezov.weebly.com/uploads/1/3/6/0/136028835/bd74be.pdfIn PDF document text
    • http://wavewozokuxa.getenjoyment.net/878490954.pdfIn PDF document text
    • http://buybritishcat.com/minuet_in_g_beethoven_violin_sheet_musicpp1mz.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/bb77db8b-9079-46e5-8c24-f29c018a8f5f/28324329816.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/722af9af-11bc-4d0f-9aeb-59060d42b53a/what_size_battery_for_craftsman_riding_lawn_mower.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/00c3124b-d2c6-4f13-be23-e7603f76d4a1/what_causes_ocean_surface_currents_to_form.pdfIn PDF document text
    • http://kopolug.myartsonline.com/jurnal_toksisitas_amfetamin.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ce252db6-e732-474f-9385-5a1b41ac28c9/minuet_in_g_major_sheet_music_violin.pdfIn PDF document text
    • http://kipejefanowisu.atwebpages.com/casio_g_shock_watch_battery.pdfIn PDF document text
    • http://nedizilunok.myartsonline.com/bestimmter_artikel_bung.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ef29a2ff-cbe0-4baf-9943-09b3a7b11d55/the_thran_mtg_book.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed2d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED2D 6200 bytes
SHA-256: 39aaf83cf4087837ea6d02374ce3f6025866a7fe3e3c3db6bd62fd67d84ab635
font_01_sfnt_off00010266.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10266 10808 bytes
SHA-256: 6e8b5abf965fdfc1e6ed9ad917fbc94cf3be27d0620849bf0f68c21869068041