Malicious PDF — malware analysis report

Static analysis result for SHA-256 95d0d6ac989debda…

MALICIOUS

PDF

77.7 KB Created: 2021-03-30 15:02:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 00dfec914035ba1fa8da954e3cffecae SHA-1: 111f4081ac36400f2b24c011bdf42ad7368b0d72 SHA-256: 95d0d6ac989debdae7fbbb5bddd5a2789c03fef46dff96d6ffac648314824253
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=d%2526d+5e+indefinite+madness PDF link annotation
    • http://kovokowem.iblogger.org/angry_birds_stella_mod_apk_revdl.pdfIn PDF document text
    • http://siderevakeforu.22web.org/7842880465.pdfIn PDF document text
    • https://labifunuvi.weebly.com/uploads/1/3/4/8/134847398/gudajiveg.pdfIn PDF document text
    • https://fofapisobav.weebly.com/uploads/1/3/4/7/134712410/tanox.pdfIn PDF document text
    • https://nadarikiwuxat.weebly.com/uploads/1/3/2/7/132712530/kisonemoku.pdfIn PDF document text
    • https://veguxalefimas.weebly.com/uploads/1/3/1/3/131382166/cbfa3f4bd75.pdfIn PDF document text
    • http://mujabelor.mywebcommunity.org/haruki_murakami_books_reading_order.pdfIn PDF document text
    • http://pakunobun.getenjoyment.net/wobeg.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jajuzasalikirut/nisokeputirulaxopixu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/414b63cf-30ab-4d1f-ad5f-a31d8f216996/42990453965.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e8c3f034-d07d-4cbf-bd99-7c7fcef12805/how_do_i_adjust_the_volume_on_my_roku.pdfIn PDF document text
    • https://367e539a-c541-4439-991c-4bf2bef2aa7a.filesusr.com/ugd/77d535_0390a8ebb2e34bf7aeba840fc108bd0c.pdf?index=trueIn PDF document text
    • http://bixerexexotepe.rf.gd/67269955349.pdfIn PDF document text
    • https://s3.amazonaws.com/jovekus/carrier_weathermaker_8000_code_14.pdfIn PDF document text
    • https://s3.amazonaws.com/jusuberu/91634383398.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a9ae49f8-de21-4c3b-a082-b3b996bd3481/sazokuboxemobukozavi.pdfIn PDF document text
    • https://728bf1be-24e3-4891-ba98-fedceca1a503.filesusr.com/ugd/3268c8_b07102d08fb044c58fc18354048c1abd.pdf?index=trueIn PDF document text
    • http://letutemoxeluz.onlinewebshop.net/ave_maria_gounod_flute.pdfIn PDF document text
    • http://worurekebisur.rf.gd/81182217137.pdfIn PDF document text
    • http://tatugenugefudef.epizy.com/nijagobigidob.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1149c9cd-1a63-46e8-9d5e-57dbf613b395/96737707254.pdfIn PDF document text
    • https://fecd0c08-032d-4b8b-b26c-6108aca7a00f.filesusr.com/ugd/a87c8b_13e0c9d6724e4c1ab05c0c8f90ed558f.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/damerirazib/business_studies_o_level_questions_and_answers.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f733.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF733 4156 bytes
SHA-256: bae8c65fbb2985f8f9e3f3f2bcf16a0f9e8e1e4a7d5ebf1135d71e3fbc9ddb2e
font_01_sfnt_off00010561.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10561 10612 bytes
SHA-256: 69de49d1d7f89019443093b3874a57441bcebcbad06602d778513784393af796