Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b72be39ede8f6ab…

MALICIOUS

PDF

80.2 KB Created: 2021-06-03 04:11:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 2dca628dcebdccdbaf31f84c08004a90 SHA-1: 7a88cfbb7ed147484890f547eecda15c04e6b813 SHA-256: 6b72be39ede8f6ab02538e7dcd069638b60888796ec5f5be169f2265d3ffc0d7
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous external links, many hosted on disposable domains, suggesting a link farm designed to redirect users to malicious sites. The presence of a URL with 'video+call+apps+free' in the UTM term indicates a social engineering lure. ClamAV and ML classifiers strongly indicate malicious content, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://coretry.ru/pbw?utm_term=video+call+apps+free PDF link annotation
    • https://newovedisi.weebly.com/uploads/1/3/5/3/135348170/8277769.pdfIn PDF document text
    • https://tenifapinam.weebly.com/uploads/1/3/4/7/134711228/rinivawavozigolage.pdfIn PDF document text
    • https://tolopexe.weebly.com/uploads/1/3/1/0/131070113/cbc3758a7ecb5c.pdfIn PDF document text
    • https://wosezobar.weebly.com/uploads/1/3/1/8/131856012/ranoxesozidim.pdfIn PDF document text
    • https://zubenori.weebly.com/uploads/1/3/5/3/135394140/kodopibamimibufep.pdfIn PDF document text
    • https://pusuliboto.weebly.com/uploads/1/3/7/5/137512591/0b0beacd31c.pdfIn PDF document text
    • https://wirumexazejop.weebly.com/uploads/1/3/4/5/134599385/9379d80e1063fd4.pdfIn PDF document text
    • https://sovakevu.weebly.com/uploads/1/3/4/3/134341498/maxelebaxul.pdfIn PDF document text
    • https://femomupine.weebly.com/uploads/1/3/4/4/134458898/rinisif.pdfIn PDF document text
    • https://zavamemedu.weebly.com/uploads/1/3/4/3/134305249/kepubuzokaxemosar.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/1765d77a-e871-4abd-8be3-38844025eb00/50566169190.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f2cb5b41-daa7-429a-b2c4-ee102ae8ad26/bram_stokers_dracula_movie_wikipedia.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/96d127a9-72aa-4472-8649-304eca09823f/is_it_ok_to_be_an_average_student.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f157c000-b21c-4530-b4e9-b62ad21105d3/putalujenusujowet.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/86b666ed-5065-480e-a253-67917bfe2ef5/politics_of_aesthetics_ranciere.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/074939f4-2ce8-43ad-9a9e-30fb4cb1d852/axial_scx10_ii_2017_jeep_wrangler_unlimited_crc_review.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7b267848-17ac-4de7-8455-a185bd50647e/vajubulanixoran.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/95ef0302-ca3c-4e70-b407-9d86ce3f46f5/71575716232.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eead.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEEAD 4716 bytes
SHA-256: 9e4838afd58b1de3f0dc6795b32815b7e8782e5045a32c2f2f3263d91f5f38d3
font_01_sfnt_off0000feb7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFEB7 11488 bytes
SHA-256: 9d777e4726200465bcaa5562b4b89c4c7d8296cbd19113f353855dba4f0f8931
font_02_sfnt_off00012417.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12417 4324 bytes
SHA-256: ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230