Malicious PDF — malware analysis report

Static analysis result for SHA-256 8aeaf2d5c3d07093…

MALICIOUS

PDF

80.3 KB Created: 2021-03-26 12:45:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: d2f9dedd1e830ac4172056891cca108f SHA-1: 99263f660a6a4d7233fee858b5d49cc8c442e815 SHA-256: 8aeaf2d5c3d07093d24d485d90ac5929731b782660f96fc6c98af9f4e62801b8
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/award?keyword=anticoagulante+definicion+pdf PDF link annotation
    • http://chebsvet.ru/hth_studios_gold_subscription_keyjxbcy.pdfIn PDF document text
    • http://igme.site/what_are_the_capabilities_of_data_mining_toolsnko6z.pdfIn PDF document text
    • http://idealica-co.site/vuzabutabupirobipib6udaw.pdfIn PDF document text
    • http://baykamif.space/asepsia_y_antisepsia_en_cirugia_bucalvbvxv.pdfIn PDF document text
    • http://loveantravel.xyz/61963992200iyzuv.pdfIn PDF document text
    • http://tomogorman.com/hack_game_my_talking_angela_ios1gtwk.pdfIn PDF document text
    • http://gutprod.xyz/nevuzavuzasamutejamoxg6vb.pdfIn PDF document text
    • http://sdek-24.cc/github_pull_request_review_best_practicesjh584.pdfIn PDF document text
    • http://newberginvestmentproperty.com/biriyani_malayalam_songs_freetsa43.pdfIn PDF document text
    • http://pixelbarista.com/10744794379awm2g.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://4e33067b-0f13-4bed-bb9c-ea95f768fd7c.filesusr.com/ugd/23924c_c434b81b33ec411da279611993997fa1.pdf?index=trueIn PDF document text
    • https://627f215e-41ba-4aa4-9906-5f9f9d117739.filesusr.com/ugd/8ab72e_1c3e17e85784483ea892db73ae49de34.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/ab5a2b72-b48d-4b69-80d8-c563dfd39db3/program_coordinator_interview_questions_and_answers.pdfIn PDF document text
    • https://8533cbf3-c0d6-400c-bdf8-8ca38cf0242b.filesusr.com/ugd/135178_cacd2a3a40a44826a167dd47943b83cb.pdf?index=trueIn PDF document text
    • https://580b68e3-2104-4118-ae5b-4f285de1c062.filesusr.com/ugd/dad7b5_2db81ba9c6a0430ea35948b8a25785ee.pdf?index=trueIn PDF document text
    • https://1dab3517-3db0-43ff-9fd6-b65b51f65b60.filesusr.com/ugd/565485_e4f2eed6137b4be58da02c8f209f59d0.pdf?index=trueIn PDF document text
    • https://da99f664-88c7-4a27-98aa-0bbcec2e8f57.filesusr.com/ugd/66f3f9_918754d90b2c49c0b3634570a5355357.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/1abfc578-b661-4574-bdac-85cb8d2c8750/ligeditezukofewo.pdfIn PDF document text
    • https://cd9ed9ec-87d1-42be-9198-0b2de6c1db4d.filesusr.com/ugd/158fb9_b101480ce2c542acbcaf0dd2f8a9ea2a.pdf?index=trueIn PDF document text
    • https://2e6726a7-2e78-456a-9fa1-8bc85c3b20a6.filesusr.com/ugd/76e31d_bdaf1d829b344352af1680ec564f3a25.pdf?index=trueIn PDF document text
    • https://1dab3517-3db0-43ff-9fd6-b65b51f65b60.filesusr.com/ugd/565485_c92689aff48e43c1a98305aecc5cb9a8.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/618afc6c-3326-4854-b2a3-9211809ba934/78210463241.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f7e9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF7E9 5036 bytes
SHA-256: 4356196bc7fb8946021aa0bf2bcfcbe612d4555fbc09d26391052a277df17a28
font_01_sfnt_off0001092c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1092C 13676 bytes
SHA-256: fb70c4adab6eebdadf2d27e9a58134dc310be9fd3f80535c41e1371b1fc13450