Malicious PDF — malware analysis report

Static analysis result for SHA-256 6beffc89d98b0500…

MALICIOUS

PDF

84.8 KB Created: 2021-04-30 15:59:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: bf73cf97bc3179edefc383db115420c6 SHA-1: 9a3c57bfa27b36ecb55669ee267f002f7dcf5c19 SHA-256: 6beffc89d98b05007a2b9c47fbda8c68c6a441c58da3d123eb359906a10329f7
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=instagram+crazy+girly+quotes PDF link annotation
    • https://fagutefoxod.weebly.com/uploads/1/3/4/2/134235025/55b27c82558.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4487623/normal_6033a5fe7d71a.pdfIn PDF document text
    • https://mitabepomumo.weebly.com/uploads/1/3/1/8/131872015/tovinasawefugesoxijo.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4421329/normal_5fca32519d759.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379732/normal_606b98c45c38c.pdfIn PDF document text
    • https://jenititufevi.weebly.com/uploads/1/3/4/5/134595561/mewosewudez_sowujabose.pdfIn PDF document text
    • https://seronenufides.weebly.com/uploads/1/3/1/4/131407086/13f443b.pdfIn PDF document text
    • https://sididipukiwe.weebly.com/uploads/1/3/1/3/131398020/viwafivekesegu.pdfIn PDF document text
    • https://zefisuket.weebly.com/uploads/1/3/4/8/134868467/neruvumujub_vejovuretima.pdfIn PDF document text
    • https://luwojasog.weebly.com/uploads/1/3/1/3/131380471/tesubajip.pdfIn PDF document text
    • https://mugabezimezik.weebly.com/uploads/1/3/4/2/134235171/4867edc6965.pdfIn PDF document text
    • https://sukorason.weebly.com/uploads/1/3/4/5/134578332/fe9789a55f8955.pdfIn PDF document text
    • https://jenejipita.weebly.com/uploads/1/3/4/4/134473981/9303351.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4390328/normal_606503df548e3.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/mufukep/asparaginase_enzyme.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b32d827a-aaf8-4863-9bc3-3f9f62da4516/how_to_check_transmission_fluid_in_2004_vw_beetle.pdfIn PDF document text
    • https://s3.amazonaws.com/mejobu/how_to_reset_a_keurig_k_elite.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c83c9614-a08c-48de-9245-407df975e13c/the_book_of_jasher.pdfIn PDF document text
    • https://s3.amazonaws.com/kakef/vanguard_index_funds_performance_2017.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/31c8445b-3c5c-4c87-9204-cdf7c156ef4a/a_cuantos_metros_cuadrados_equivale_un_lote.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/765ee187-6dde-44b5-9e95-46b1d422b793/fezalidilokatado.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ae257cf4-4248-4929-8746-d7b6f8cdd369/how_old_is_my_hotpoint_appliance_by_model_number.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/84802c4d-d586-4e07-a331-b355e09be42a/badger_5_insinkerator_clogged.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/13c62a28-1c3f-4d0e-afca-734306d7b180/peavey_vypyr_30_review.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7b66ad91-be90-4acd-b8d6-71f7c7bf46f4/fairy_tales_books_for_first_grade.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eb762398-9eda-407e-9856-c07a710a1179/what_is_the_formula_for_sum_of_geometric_progression.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/518ef405-6425-4974-98de-06ef5a4cb7de/who_is_the_queen_in_the_crown_season_5.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010dbf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10DBF 5336 bytes
SHA-256: af77427f493d0ec8f2c68bd423357a7e216c80071079477bb273e45407e9eacc
font_01_sfnt_off00011fe4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11FE4 11136 bytes
SHA-256: b619d98c0395723b11c3007c81038605e054a98157c56b61561cb46812960950