Malicious PDF — malware analysis report

Static analysis result for SHA-256 6eb834ab0d41ca3d…

MALICIOUS

PDF

80.3 KB Created: 2021-04-06 09:40:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: dc227eab8d3051ca9d92a7a828bce27c SHA-1: c8bd4475847e6697d787b6b7a8ac71619463dc92 SHA-256: 6eb834ab0d41ca3de9956173abbafd131eaf0f7c867afbcc78407fb15894a68a
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/aws?utm_term=who+appoints+audit+committee PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4384164/normal_601b51d36db1e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4380403/normal_600c1d0caf4c5.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4494866/normal_5fc9aa4feb2dc.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4476285/normal_5ff16d1e20092.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367940/normal_5fdae0fcc62d3.pdfIn PDF document text
    • http://all-casino.xyz/decision_tree_algorithm_in_machine_learning_tutorialk5gj8.pdfIn PDF document text
    • http://yesstore.pro/ronexowifumuv0653.pdfIn PDF document text
    • http://vipmanmarket.space/towigosijh7yx.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/ef0f7090-503e-44bf-9932-0671e837d70b/19259056881.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bf40bfdd-9128-47ec-8329-64819261f5a0/ms_word_design_templates_free_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ffdca9d4-248e-4f7c-b31d-232fea077ddc/nustep_trs_4000_weight.pdfIn PDF document text
    • https://920f4c01-5fd6-4c40-8b27-b99972fecb60.filesusr.com/ugd/d63aaf_8f425d9054394eee94c6b3a88fb34b3b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/24d25a98-539e-4a16-bc4d-c77ff1cd217c/26460433605.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6a801fe6-f9ca-405a-a97c-83d20dbef516/mha_ib_acio_2020_exam_date.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/680116d5-a434-4d89-b725-fc91f5bd8e30/nudutamovoxeduxadurodir.pdfIn PDF document text
    • http://ruxusanufip.rf.gd/free_cash_flow_example.pdfIn PDF document text
    • https://bff5fdab-9fd0-4670-908b-a1308bb5a9cb.filesusr.com/ugd/227d0f_49c0897a9d48479bbc7f2c8f2a6373fd.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/7dfe8cc8-a79e-4f74-beb3-3e7a397d3fd8/59896548592.pdfIn PDF document text
    • http://wuvuwipiwizovid.epizy.com/44956950840.pdfIn PDF document text
    • http://ditinalozevid.epizy.com/addison_wesley_math_makes_sense_5_answers.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8a4f6356-1a28-444e-a41c-d62555613c92/85830761581.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8930b168-60e6-48b8-806b-9a0d5d748351/35288038179.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/82878638-0c55-4570-8081-a94d1eab68bb/how_to_crochet_a_small_dog_sweater.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ff18.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF18 5196 bytes
SHA-256: b5c8c1986dfa6abe7b796057709c823ed9a035e2a8320dd341ed70c62e0290cf
font_01_sfnt_off000110ac.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x110AC 10264 bytes
SHA-256: 333aa7741bb659ba5c0524c1852beb0d8b001151180c85c064541e10979e1e27