Malicious PDF — malware analysis report

Static analysis result for SHA-256 80d5e20040ec7e16…

MALICIOUS

PDF

77.7 KB Created: 2021-04-01 14:40:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 7544205058b368d47196935d2335394e SHA-1: 5d02553a53b959d51c858d602e9bfe246f0db7c8 SHA-256: 80d5e20040ec7e16fb0883338b8d6f795fbcb411b8f08e5287c2f23095e5cff5
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/award?keyword=cessna+172n+parts+catalog+pdf PDF link annotation
    • http://laribij.scienceontheweb.net/19742965270.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4476140/normal_5fe15232d41a1.pdfIn PDF document text
    • https://nuniladolu.weebly.com/uploads/1/3/0/7/130775245/8779484.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393506/normal_6052ece4d799d.pdfIn PDF document text
    • https://kazobutuzag.weebly.com/uploads/1/3/1/1/131164075/597dc.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4493888/normal_5fcad82584236.pdfIn PDF document text
    • https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/836ff.pdfIn PDF document text
    • https://damemebu.weebly.com/uploads/1/3/5/3/135316778/8d9aaa3d3.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4426549/normal_600299e2c1abc.pdfIn PDF document text
    • http://fomoregekamikat.mypressonline.com/bitdefender_gravityzone_advanced_business_security.pdfIn PDF document text
    • http://newipufisatag.scienceontheweb.net/data_structures_and_algorithms_analysis_in_c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4447276/normal_602b54ff16abf.pdfIn PDF document text
    • https://vadurevagide.weebly.com/uploads/1/3/3/9/133999829/fafutil-wefara-gemixaf-vosesijepov.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/9fe59824-07b6-4c07-9fbe-301e1d372a04/68300779848.pdfIn PDF document text
    • https://b7af6bb9-01eb-4839-ab56-764651de4344.filesusr.com/ugd/2486b5_cc799ec5791e42c981c4f1d9fd6dc284.pdf?index=trueIn PDF document text
    • https://e1318bff-d970-45e2-bcea-45481503a18b.filesusr.com/ugd/75a96d_01212379a2a242f79bab0a28a021572d.pdf?index=trueIn PDF document text
    • https://4f640d82-8365-4c22-93d6-dbd3427c3fb0.filesusr.com/ugd/55e8b7_6e2f6502321444cdbc8b6e0711447b9f.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/38563667-6dd4-4279-85c2-e4c754bb5fda/tp-link_tl-wr841n_wifi_password_change.pdfIn PDF document text
    • http://wozimape.onlinewebshop.net/inspired_beginners_spanish_podcast_13_el_futuro.pdfIn PDF document text
    • https://46d16763-6c5f-4e19-aa2c-3f4071fcbec2.filesusr.com/ugd/26f730_c787c2a6379841758ec8147d69fa1a27.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/509cf62d-d599-4075-ac71-653d24e8ba45/pizutoxavisuzupomegev.pdfIn PDF document text
    • https://36c7e617-1221-4173-b726-d5bce2878801.filesusr.com/ugd/610d21_3b50b3a5cc6a48a09664fc42f0e0b6c8.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f045.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF045 5492 bytes
SHA-256: 8c2ae2f6469b17c45ab76be6026bdfcfd3353d114e0ad384baabb67ea9558ec0
font_01_sfnt_off0001030c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1030C 10784 bytes
SHA-256: 3f7429ae106ecdc3710a082cafcccfc3156ab49bb8dc6fa183cdc141c4d61bb3