Malicious PDF — malware analysis report

Static analysis result for SHA-256 6dbfed5a0ea5da57…

MALICIOUS

PDF

77.7 KB Created: 2021-06-12 18:53:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: e6f7a464e15440d643802465e9294558 SHA-1: 53a05c6ae49ce2a107693908cc516dc554be9ced SHA-256: 6dbfed5a0ea5da57730b37f0486c37e8c54d1e29b663345697463a8372103ff5
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to disposable hosting, indicating a link farm or phishing attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a malicious document designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9952

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://smidgel.ru/pbw?utm_term=cs+1.6+intelligent+aimbot PDF link annotation
    • https://static.s123-cdn-static-d.com/uploads/4459177/normal_60b46b11f2021.pdfIn PDF document text
    • https://rubuvewoxuvima.weebly.com/uploads/1/3/4/8/134873715/vonabunaxesilow.pdfIn PDF document text
    • https://gapeduruje.weebly.com/uploads/1/3/2/6/132681343/guwapug-vutezixavozawib.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4483081/normal_603e2bfcc09bd.pdfIn PDF document text
    • https://bewuzitavunu.weebly.com/uploads/1/3/4/3/134349104/ganegexekija.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455399/normal_5fd0fb1820235.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455883/normal_604952c5d5191.pdfIn PDF document text
    • https://nulesurusisozi.weebly.com/uploads/1/3/4/7/134744420/4629298.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4413983/normal_600035d22db94.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4404107/normal_600648326e186.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4447098/normal_5fdb08e148643.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/edc76d4e-8958-42ed-83ff-ac52114df537/how_to_pair_my_airpods_to_my_samsung_phone.pdfIn PDF document text
    • http://zikupuzajix.pbworks.com/w/file/fetch/145042431/class_6_algebra_worksheet.pdfIn PDF document text
    • http://kapetipubi.pbworks.com/f/flexible_work_schedule_agreement_form.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a77c8320-71e3-421a-ba4a-98474ef33562/guwetakesu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4219d861-67b5-465e-933f-91689ded373d/bulejamufarojikovide.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/af1c9539-c622-4c18-8b7d-19ceee20f09b/how_can_the_properties_of_rational_exponents_be_applied_to_simplify_expressions_with_radicals.pdfIn PDF document text
    • http://jesababa.pbworks.com/w/file/fetch/144413952/how_to_get_macro_on_agar.io_ipad.pdfIn PDF document text
    • http://pibadaro.pbworks.com/w/file/fetch/144582693/old_assamese_film_video_song_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cd50d83b-3d63-494b-8b57-b8581843eb6d/lldm_cantos_2020.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f221ccd2-d78b-41f8-983d-5c01e4a53ba3/why_is_my_hp_deskjet_2600_not_printing.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3f250bcf-de25-4c95-a4e2-d9bd12641450/89740356554.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/085b9cde-34dd-4833-8061-7b9ec0eb89a0/loreal_frost_and_design_h85_instructions.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ae39460f-fa67-41ff-8f8b-8fca952c3436/43582439038.pdfIn PDF document text
    • http://goxuluk.pbworks.com/w/file/fetch/144793656/tawagosapivaf.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/96fa85fa-5fa5-427c-acf8-7744c17ca723/teweziwojugomugikojeve.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d983.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD983 5096 bytes
SHA-256: 6c046217957ed79ca9cd2f2a076128877304b5aeaa9f8539a38953747b1629b5
font_01_sfnt_off0000eac9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEAC9 15348 bytes
SHA-256: 642b21c2373deb998cdcfcd618d47bc6482b2f56399cebbc606db01ef0797d91
font_02_sfnt_off00011904.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11904 4324 bytes
SHA-256: 4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3