Malicious PDF — malware analysis report

Static analysis result for SHA-256 9693cc20fd82eb63…

MALICIOUS

PDF

89.1 KB Created: 2021-03-25 06:57:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: e208fd745466fa5fdc3b18fccbde64a6 SHA-1: b26b405b0609c973fac4eb812c0568967ea3fb48 SHA-256: 9693cc20fd82eb6324ac2cfe4860a291ada14bcdca4bf4d8c50a926897e3bdda
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/123?utm_term=define+anthropometric+form PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4368496/normal_5fcce1226f215.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4495413/normal_5fd3c997687d0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4449775/normal_604ba417a5b47.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4407302/normal_604acb9425de3.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://5c71d6b4-13b5-43a2-97a4-9a0eba4d0f4d.filesusr.com/ugd/0f1814_ebbc64fcc7f847b9ac0d1d7bf3343404.pdf?index=trueIn PDF document text
    • https://e9abb47e-19e5-4ec2-9f3c-2aa4e6f2bf0a.filesusr.com/ugd/92be99_6b980a6a82964bafa9af788fc72796d7.pdf?index=trueIn PDF document text
    • https://9f9bd9fa-00fe-4673-b34e-9a629881f524.filesusr.com/ugd/09273f_1ae27674445c49efa50ed002404c03c0.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/tometubufimopim/ultimate_background_eraser_mod_apk.pdfIn PDF document text
    • https://1a2149e7-ca7f-4e7c-a584-0e483de6f3af.filesusr.com/ugd/9219f8_5f414695ee42455981fa8bc00e884280.pdf?index=trueIn PDF document text
    • https://dc6b22d1-fd3c-476a-b8f1-b0505981f591.filesusr.com/ugd/ab5adf_fe9aef7782884c58ac2be5b86488700e.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/gusule/peviroxoso.pdfIn PDF document text
    • https://97a45c9e-1ab5-462a-bfe2-fded34b9a8b9.filesusr.com/ugd/b50c55_c9bbfb8e1ce4454fbe69891b393a3b22.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/kumasala/digitosalupunepefamedibu.pdfIn PDF document text
    • https://5d9de69b-f80b-44d6-9c2d-9027806fef0b.filesusr.com/ugd/e26ad2_0938296f84cf4e619fb76f96c5904ca4.pdf?index=trueIn PDF document text
    • https://6525eaf8-9a42-4119-9fb4-c3d475b3b78e.filesusr.com/ugd/80bfa9_bea161a589ed4566987735b021e6bcbb.pdf?index=trueIn PDF document text
    • https://f405dec1-7f90-4f4c-a861-5286f67d0127.filesusr.com/ugd/ab922d_f83f9c715ae64835b7840116caae7fea.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/xakapudakadu/44107593522.pdfIn PDF document text
    • https://s3.amazonaws.com/rijaliwiguvex/91571941411.pdfIn PDF document text
    • https://f608bf75-187c-4b28-9621-af925c05c2b6.filesusr.com/ugd/05e3ad_bedd9f5333b04ba999b4d965176ff7dd.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/kelageketisefuv/baby_frida_humidifier_not_working.pdfIn PDF document text
    • https://c3e810f9-371e-40b9-9a0b-4695a496ec77.filesusr.com/ugd/2c7c49_f7f36cd7087d4999a15ea088c150edf7.pdf?index=trueIn PDF document text
    • https://3633ae4e-9acc-45df-885e-1bfa1481cb44.filesusr.com/ugd/e73054_0fbe751875c945d8937e1302d47ba04a.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/wazagidonux/zanoxasofuzaluvor.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001164d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1164D 5044 bytes
SHA-256: 7f78a5fb4e12511a9a04f050c32007f7929cb47a3cec6638624deb2e11882351
font_01_sfnt_off00012753.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12753 14408 bytes
SHA-256: 2c931a72d65cc8a2b13c65a65353f627baa1340b24584b4cee0f59e2a8ed753a