Malicious PDF — malware analysis report

Static analysis result for SHA-256 65480acfa98f3be2…

MALICIOUS

PDF

75.4 KB Created: 2021-03-25 04:08:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: ae73b94e3f76cd28f13144c9c7f5ebd9 SHA-1: 56509696fc08aa0803832101ade186f99b551d20 SHA-256: 65480acfa98f3be255968905221411266eb4367c9dd402ac8079fad45df2dc09
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=chemistry+connection+meaning PDF link annotation
    • https://cdn.sqhk.co/nananava/jghDjgf/57099391406.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4463010/normal_60084c4ea61d6.pdfIn PDF document text
    • https://cdn.sqhk.co/falupuvevore/ha6Jgcf/cosmos_flower_colors_animal_crossing.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393035/normal_6032127ba0f40.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455377/normal_605858a551e90.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4406191/normal_5fe78484e7d94.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://5a8aee2d-3d68-4c09-98ed-743c9c56d6fd.filesusr.com/ugd/460efe_afeca6b729fe4612b1bc2775df5e0a96.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/belopudevuzuza/appendix_11_form_medical_reimbursement.pdfIn PDF document text
    • https://s3.amazonaws.com/desekusoxi/7_continents_worksheets.pdfIn PDF document text
    • https://s3.amazonaws.com/xamibebulosaxug/xifobo.pdfIn PDF document text
    • https://s3.amazonaws.com/kegovev/89207041796.pdfIn PDF document text
    • https://s3.amazonaws.com/zumezeviwakiz/how_much_do_naval_officers_earn.pdfIn PDF document text
    • https://s3.amazonaws.com/wujixus/concierto_de_aranjuez_guitarra.pdfIn PDF document text
    • https://s3.amazonaws.com/fifomi/kerili.pdfIn PDF document text
    • https://4eff3ec4-d147-45d1-be73-876d9e1d0019.filesusr.com/ugd/efb3f0_293d2a56ed924efc9572222719f96e84.pdf?index=trueIn PDF document text
    • https://c2093f15-f4fb-4bda-9582-db5404103fa6.filesusr.com/ugd/b28561_1b592d7139ad45f8b81429028ca2117c.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/vuxagixil/formation_brancardier_ile_de_france_2018.pdfIn PDF document text
    • https://s3.amazonaws.com/niporofez/epfo_claim_form_19.pdfIn PDF document text
    • https://d04c2b29-3777-4fe6-aaa9-ab96f87c3324.filesusr.com/ugd/43eb95_b43b8576140b4115b1de26f0fde234cf.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/bibejovixapis/5452504379.pdfIn PDF document text
    • https://s3.amazonaws.com/fosalizuzu/arifureta_web_novel_espaol.pdfIn PDF document text
    • https://s3.amazonaws.com/genijusemu/high_sierra_hydration_pack_instructions.pdfIn PDF document text
    • https://s3.amazonaws.com/wajibile/56283148168.pdfIn PDF document text
    • https://c7ecfb45-4de9-4174-91ae-4a3416e09b0d.filesusr.com/ugd/fc4f66_4b9f51c5fb4046ec9ac759d4d58c4756.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/liluvad/gikoxekifaneragot.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea51.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEA51 5188 bytes
SHA-256: 231bf8a3e0f2e5c3dbd673b476eced831b907210331878d439b4edd2db526af5
font_01_sfnt_off0000fbcf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFBCF 10668 bytes
SHA-256: 4f8bc7f757524560568f8a43fedb61a03c93f56cbf8cccee9dfb9546ea506d06