Malicious PDF — malware analysis report

Static analysis result for SHA-256 842b892aa054db23…

MALICIOUS

PDF

75.5 KB Created: 2021-03-12 19:49:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 0b16343dd511bed4b272c1cae5c5306f SHA-1: 1a72925190b1f03ea00f593bd683764fc8568129 SHA-256: 842b892aa054db23b1a1d1991a35508ef92d065e83a67ee65da905feb8a7381b
134 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm and presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/123?utm_term=gapps+cm+13+6.+0.+1 PDF link annotation
    • http://petajofap.22web.org/fufevoregevitudipuz.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4404297/normal_60311449b3cc4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4414498/normal_5fdb1b7c57197.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4484383/normal_600da3d8ee851.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4391920/normal_5fc6b821dd594.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/db2765fe-f220-43c5-a04a-22b80105bd15/what_genre_is_fantastic_mr_fox.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5daabd8e-802c-4600-9749-ee023f07529f/how_to_keep_formatting_in_word.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eb69be1c-0f53-4e92-82be-bc7f3b791037/how_long_do_i_cook_steak_on_foreman_grill.pdfIn PDF document text
    • http://pavasokunise.epizy.com/why_is_my_nespresso_light_blinking_orange.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a19903ab-c171-4781-8391-8954a56bc5d4/what_is_crp_in_blood_test_in_malayalam.pdfIn PDF document text
    • http://vamagirizotaro.rf.gd/reformed_theology_assurance_of_salvation.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bc0a73a6-6700-408b-96d9-80801e33c8d2/how_to_set_adt_alarm_system_at_night.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/88813d86-750c-4b4b-ab6f-cd00dce6f922/p90x_fitness_guide_download.pdfIn PDF document text
    • http://zebigibozudival.epizy.com/wagaseje.pdfIn PDF document text
    • https://s3.amazonaws.com/kelukakeb/mumosukeputusekubases.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/61ef9e29-1040-429e-9c9f-670bee20a86c/ejemplo_de_monografias_universitarias.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6d9dcbe4-09ce-4563-8574-f7eb9bfac248/how_do_you_put_houses_in_monopoly.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4e9e1234-2aef-4808-8ff1-0723590d73cd/dewalt_miter_saw_stand_dwx724_review.pdfIn PDF document text
    • https://s3.amazonaws.com/davubewu/dinosaur_king_game.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/17f7d355-af83-45fe-847c-b5fb7fbc062b/77682332002.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dfb3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDFB3 5528 bytes
SHA-256: d43f2841151012c9fcf1c7c3ff8a77e02491eab49b768882929da83dd183b0c5
font_01_sfnt_off0000f271.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF271 3720 bytes
SHA-256: 6539b129c5cd894636dc8f40f53a156c00c8f46378ab4f137c96d687a1cff6ed
font_02_sfnt_off0000fdd4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFDD4 10264 bytes
SHA-256: e332ded44cf0cdd701cfbe33587fb9febd8b6cf9f834a2501ba66a24bf55d875