Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f6779c12abb5dde…

MALICIOUS

PDF

79.5 KB Created: 2021-06-11 18:16:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: 893f49529e86274908050f1ce3ae4af0 SHA-1: 3cfb875734755a6eb91f703b8bd96fb2567e70c7 SHA-256: 7f6779c12abb5dde1ad06d3c1aa9fe3f119f4ca6bfc5923e272e168fd5c43c1c
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by ClamAV and an ML classifier. It contains a large number of external links, many of which point to disposable hosting, suggesting a link farm or SEO manipulation tactic. One of the primary URLs, 'https://pistant.ru/pbw?utm_term=standard+lease+agreement+format', appears to be a lure for users searching for lease agreements. No scripts were extracted, but the presence of numerous external links indicates an attempt to redirect users to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pistant.ru/pbw?utm_term=standard+lease+agreement+format PDF link annotation
    • https://vapulorefemefiz.weebly.com/uploads/1/3/5/9/135956910/soduzozezujufu_kofutoze_pawogedadenaj.pdfIn PDF document text
    • https://nimukitu.weebly.com/uploads/1/3/4/2/134266418/5305207.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4403429/normal_60b94dcee2dbe.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4453914/normal_5fdcd28b37b61.pdfIn PDF document text
    • https://vunamesu.weebly.com/uploads/1/3/5/3/135324142/8514325.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4472763/normal_5ffda767d7368.pdfIn PDF document text
    • https://kuxiwapanipajof.weebly.com/uploads/1/3/0/9/130969705/7984171.pdfIn PDF document text
    • https://pigofularujatuf.weebly.com/uploads/1/3/4/3/134360020/benojabolewufol-dufegufimijim-sorokujowu.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4445866/normal_5fc66b1317e57.pdfIn PDF document text
    • https://lalojitewimagix.weebly.com/uploads/1/3/5/3/135304200/misenoligile-vavumukawonun-negabef.pdfIn PDF document text
    • https://zamamuxito.weebly.com/uploads/1/3/4/2/134234866/mazarobel-gasududuxanide-liburufoka-midadepaxanim.pdfIn PDF document text
    • https://rutebamem.weebly.com/uploads/1/3/4/8/134862863/simunotor-pusurubaju-woribugenabo.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/5f47e236-5b6a-45db-9bbd-26140e2c9baa/troy_bilt_pressure_washer_3100_psi_2.5_gpm_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/54fdd235-e378-4a10-90ff-6a3fea5c272c/35926575918.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/df6e72e6-e34d-4b0c-871b-927afa1b8f5a/82344921542.pdfIn PDF document text
    • http://tozuxexap.pbworks.com/f/what_are_the_16_regions_of_ghana.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fce27bc8-32dd-443f-8090-67e05f0b2b4d/bloons_td_6_version_1_6_apk_neueste.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8b1e5d43-e48e-4c95-8237-6cffaa4718d2/14640673955.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d94a95e4-466f-4ded-bd2e-aa090f7584b7/contextos_leccion_3_worksheet_answers.pdfIn PDF document text
    • http://tagutijak.pbworks.com/w/file/fetch/144962580/rick_ross_money_dance_mp3.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e8623fb3-530c-4aa2-b7d3-e6b84cd64563/cleric_archer_handbook_3.5.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f7dc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF7DC 5332 bytes
SHA-256: a44e696571aae2eb717eae54bc71b09de63a93a3a8433a93b7cecf510eea2346
font_01_sfnt_off000109e6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x109E6 11292 bytes
SHA-256: 55be9d718854021d8a1bfa58a0d469d16f41f11d0c84d18ed0472bd4704b7e8d