Malicious PDF — malware analysis report

Static analysis result for SHA-256 8e886fa06162737d…

MALICIOUS

PDF

83.5 KB Created: 2021-05-06 01:36:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: 9c657250a35e0440209516a269f5862c SHA-1: 1dfd301dba0735cd42ebcf7a9ba2d7b23432b5a8 SHA-256: 8e886fa06162737d4b3a0bcd3b8c6a0df2f84459d0552f7da5d118ded3156a6c
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/strik?utm_term=what+age+can+you+get+your+permit+in+mississippi PDF link annotation
    • http://bostpolamos.site/vmware_certification_guideqjv8q.pdfIn PDF document text
    • https://genezekanoz.weebly.com/uploads/1/3/1/4/131413678/a2ee190814.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4458616/normal_602b6d65d0a95.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4411252/normal_5fcf12f2beb9e.pdfIn PDF document text
    • http://prizinsta24.online/burnout_video_song_hdyaar._comb7s7i.pdfIn PDF document text
    • http://bcpzonasegura10beta-viabcp.com/child_development_worksheetsb0xdk.pdfIn PDF document text
    • https://kawikixefi.weebly.com/uploads/1/3/5/3/135388441/gevezen.pdfIn PDF document text
    • http://myfavoritesun.xyz/63125493130zuc05.pdfIn PDF document text
    • http://topcreditmonitoring.info/zuzudedutamapudetaxiwoik52f.pdfIn PDF document text
    • http://mbfsopg.com/stihl_ms_170_bar_oil_adjustment70tth.pdfIn PDF document text
    • http://fsfsfd.xyz/muwugitasipugasi8y3n.pdfIn PDF document text
    • http://italylife.pro/algebra_worksheet-_section_10._5_factoring_polynomials3qhl9.pdfIn PDF document text
    • https://cdn.sqhk.co/zagekexeroze/ibHogj7/authorization_format_for_gst.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413465/normal_60265cfb87e88.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4426073/normal_5fffc106c03a6.pdfIn PDF document text
    • https://cdn.sqhk.co/tezabulaw/hdcqri8/avery_label_templates_8167_christmas.pdfIn PDF document text
    • http://pro-gram.pro/jidedanoveto5dp5o.pdfIn PDF document text
    • https://cdn.sqhk.co/zolilobup/ihkk0O5/dunudafuxejojefinezusu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/dd1b51b7-e6da-43e4-bfdf-6197f7cf6f97/27821874841.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5c1dadda-9068-4111-94fc-1ea5f9274048/can_u_get_money_from_being_tiktok_famous.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/14a8056b-a0bc-46b8-8407-6edd184ada40/87023454670.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fe8d9559-a899-40b3-8d9d-d2340fdadd81/2nd_grade_math_equations_worksheets.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eb331ea7-e57d-429f-a891-828c0910408e/first_alert_co400_3_beeps.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fa19.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFA19 5312 bytes
SHA-256: 51305752878f9e33e49ab6e5cf6d06cf05d7065f27e50aca4720f71a0addcc3e
font_01_sfnt_off00010c0a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10C0A 11076 bytes
SHA-256: 81564703cb3bc6af71e60b48211e49de50f2d385c26963ade73cb9b08a95212e
font_02_sfnt_off000131e2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x131E2 4324 bytes
SHA-256: cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34