Malicious PDF — malware analysis report

Static analysis result for SHA-256 6e855c450a31fdcd…

MALICIOUS

PDF

72.2 KB Created: 2021-03-19 04:28:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 3f4d7edcfaa4e8ac1eed46efd04506c7 SHA-1: 9bf34f0e7f36c36480d1fff87d8b6befa073d247 SHA-256: 6e855c450a31fdcdebc912ebd58d3f2408c1f7301efd6c72e61f8e0b83c1dc7d
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8170

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/award?keyword=puntos+de+acupuntura+para+bajar+de+peso+pdf PDF link annotation
    • https://garururukipu.weebly.com/uploads/1/3/4/2/134235121/nagapesaxitak-kujotekilud-nikag.pdfIn PDF document text
    • https://tukumexof.weebly.com/uploads/1/3/4/7/134721389/bb5d2803b.pdfIn PDF document text
    • https://gegirugotosizuk.weebly.com/uploads/1/3/5/3/135397722/vibegujepiso_puvage_werokexar_belupebetin.pdfIn PDF document text
    • https://ruxunomitebapat.weebly.com/uploads/1/3/1/6/131606858/lasopunawizox.pdfIn PDF document text
    • http://xuxisozolawub.22web.org/13196111348.pdfIn PDF document text
    • https://dufubixapitosig.weebly.com/uploads/1/3/4/5/134503348/4688952.pdfIn PDF document text
    • https://dunebuka.weebly.com/uploads/1/3/2/6/132682868/lowaduxi-wonibetat.pdfIn PDF document text
    • https://sujujawajiz.weebly.com/uploads/1/3/5/9/135964945/buxawizipolumugivofa.pdfIn PDF document text
    • https://toxoladosa.weebly.com/uploads/1/3/4/4/134479392/wobemidixuxogeri.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://koxikid.epizy.com/90872709011.pdfIn PDF document text
    • https://3794eb9c-cc8b-492c-aecc-44533f76aaa6.filesusr.com/ugd/1ee69b_b99ba520e505408794131a71539460c1.pdf?index=trueIn PDF document text
    • http://bulexaresozo.rf.gd/daduxuzux.pdfIn PDF document text
    • https://af30af13-e0b7-4de0-aca7-7783c01eade2.filesusr.com/ugd/9757e7_b5c4a4c60a6d4fdcaee8645d14f97046.pdf?index=trueIn PDF document text
    • https://d0fd22f1-78bd-4368-960d-2a324028b2bb.filesusr.com/ugd/a4d998_550dc74e772d477183ace3373c7b2e2d.pdf?index=trueIn PDF document text
    • https://6a1e2a5f-c456-4288-b9d5-5378f87870fb.filesusr.com/ugd/076fac_8811b5ac4e7340cea8963d30cf4489b7.pdf?index=trueIn PDF document text
    • https://c5c27394-2042-4749-9b39-d1c24dcbd9f0.filesusr.com/ugd/e9b987_9707aa9990324adc80ca3bc53bf10a7a.pdf?index=trueIn PDF document text
    • https://107a3552-ed21-4f5d-95e3-510b6eae4444.filesusr.com/ugd/21bbef_6072748d357443dfb72daf1c59a85cf0.pdf?index=trueIn PDF document text
    • https://e791dc30-71fd-4519-a75e-453748eb9c32.filesusr.com/ugd/8a5fcf_1e08109b2c5e4feea8aa1b40341b6d39.pdf?index=trueIn PDF document text
    • http://xivonopegag.epizy.com/libro_sobre_valores_humanos.pdfIn PDF document text
    • http://gasukexopesifu.epizy.com/axel_f_piano_sheet_letters.pdfIn PDF document text
    • https://938a05da-450f-421e-a59b-0448473a402a.filesusr.com/ugd/cb5dea_4a7ea1b49bb5447a8ea24d37b53c2bfe.pdf?index=trueIn PDF document text
    • https://75a697d3-84f0-44cf-bab9-f05e37020c50.filesusr.com/ugd/7c3584_a51190c6eab847abbc2591014ec4ab0f.pdf?index=trueIn PDF document text
    • https://abbf68a8-5b21-4996-91be-11266bd273ed.filesusr.com/ugd/9374a7_fe5ed6441a764484a140e98f510184ca.pdf?index=trueIn PDF document text
    • https://1a447ccf-a6a5-490c-ad31-399ae8169532.filesusr.com/ugd/cf5184_6976fd64d20b442195f02062a425b7f7.pdf?index=trueIn PDF document text
    • https://04a80c79-134c-446e-801b-0c1635678e59.filesusr.com/ugd/5cebf8_154524d264b94e9db1565e9031492755.pdf?index=trueIn PDF document text
    • https://a97be2a3-bfb5-42de-bba9-b145341b31aa.filesusr.com/ugd/1f2860_9a731b958f2c4622950a9b7e02d1cc4f.pdf?index=trueIn PDF document text
    • https://e924225a-aa46-4bfc-8e56-7341551e1833.filesusr.com/ugd/54dfea_58b1f62cf1874248bbba53f9e227c33a.pdf?index=trueIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010baf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10BAF 5168 bytes
SHA-256: 1ec1c6ffa9ecd170129f3d06bcd4b621c516cc3f59f57df7391de0f90b47b295