Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e2b2420995ffa50…

MALICIOUS

PDF

77.9 KB Created: 2021-03-24 17:03:36 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 8e2ff6ded8c61e45592458d77a3a04e6 SHA-1: c1f26ad8859c5c4cbbed64f5661e031196b475a9 SHA-256: 7e2b2420995ffa50f93aa67c497fa070f7fc516c5edfa4684cfef4c5dfe6cb97
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/wix?keyword=lorain+county+auditor+homestead+exemption PDF link annotation
    • http://zazorin.scienceontheweb.net/what_is_the_main_message_of_the_tell_tale_heart.pdfIn PDF document text
    • http://palupalukagu.mygamesonline.org/32902140975.pdfIn PDF document text
    • https://sibubusede.weebly.com/uploads/1/3/2/6/132682984/xunebufutesiri.pdfIn PDF document text
    • https://bajerezera.weebly.com/uploads/1/3/4/0/134016740/936edb9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4489599/normal_6044d37ac731b.pdfIn PDF document text
    • https://dexedurifeduner.weebly.com/uploads/1/3/5/3/135346612/gefopebuke.pdfIn PDF document text
    • https://welavomuwaj.weebly.com/uploads/1/3/4/6/134633166/4180670.pdfIn PDF document text
    • http://zijafanovidiz.sportsontheweb.net/meyer_e47_plow_manual.pdfIn PDF document text
    • https://bibomezu.weebly.com/uploads/1/3/2/7/132710601/pakibalifanetugune.pdfIn PDF document text
    • https://finolija.weebly.com/uploads/1/3/4/6/134625313/aded854066.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4370286/normal_5fc9b84be476c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4393019/normal_5ff96bc076b67.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4371523/normal_5fdda39bc8cc7.pdfIn PDF document text
    • http://jebebixazonutug.mypressonline.com/el_lazarillo_de_tormes_tratado_1_la_venganza_analisis.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/298f55ac-e977-4541-b2cb-ccd5bdfbf8ca/gewavubuviwamozowav.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d68d7b4f-da8a-4c83-9bd2-200d513498e3/why_are_official_crime_statistics_not_always_accurate.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f3a0ddf3-ec44-4936-a4b4-8d8d878a72f5/how_to_glaze_kirkland_spiral_ham.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f18b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF18B 5392 bytes
SHA-256: 16dd5b91df8aea372334f33920b2f25231ff84f9febdcf77f7fe4475fab7b469
font_01_sfnt_off000103c7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x103C7 11200 bytes
SHA-256: a30ca2cd779f51148d0fa13dc8c18c41ca00b43ca2e0dfff05290bc4fb8fe62d