Malicious PDF — malware analysis report

Static analysis result for SHA-256 97ffcf3ebd13f243…

MALICIOUS

PDF

77.2 KB Created: 2021-03-09 20:41:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 11acf28569f16b320019efb363f3b1ff SHA-1: b03466f38d24e4b3569ea1d2ff021f4c58c19af4 SHA-256: 97ffcf3ebd13f243cb6ed25b0f9197676cf903c24ed30436e33af916e31dc37f
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/strik?utm_term=moen+monticello+kitchen+faucet+parts+diagram PDF link annotation
    • http://naturapple.space/car_game_pc_windows_7wswxm.pdfIn PDF document text
    • http://hiziryigit.online/barclays_app_android_pta2x7.pdfIn PDF document text
    • http://dkshlyap.ru/kijurudatefopidenalubv7lec.pdfIn PDF document text
    • http://changely.club/what_is_tawheed_in_arabic0m4ym.pdfIn PDF document text
    • http://mini-cam2.club/lumugokojiridemuzesefuxn36m3.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://409b2d23-5c1d-402e-97df-26c0da9299b0.filesusr.com/ugd/2e3d42_169920dbe4954d4e9a603161b51ad6a0.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/f9492141-cd2e-41f2-85c6-f8a8487fb6c0/winter_forecast_for_eastern_oregon.pdfIn PDF document text
    • https://8d94caac-80d5-4f6d-a73a-04ed47837dc1.filesusr.com/ugd/585b1d_d496e1705c9c4f249c45c53ffab46a91.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/4ea8a53d-ae53-4696-b5df-c114bc23eb91/are_chicken_soup_for_the_soul_stories_true.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/71db37d0-5cdc-4523-8f61-bbc0c1cef4fb/25030416747.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8f88771a-0afe-4757-9360-94a4da47a4b3/bose_sounddock_remote_control_app.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4701a058-f91b-4ed8-854b-8f329590cba6/how_do_you_reset_a_netgear_switch.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/884e526c-0572-41d3-ae7e-ea00d6eea9b0/who_are_the_best_suspense_authors.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cfc3be63-fd62-428c-b3da-8aede9ab0e0a/xonutaruwelisi.pdfIn PDF document text
    • https://5a4e7950-e122-4b3c-9cf7-894e7f5b1216.filesusr.com/ugd/76aeb6_363c3f93ca3f4404967954efcb16921b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/82eb55f9-8cb5-494f-91c5-e12ad5268e22/34213073790.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/428ddbb6-a944-4808-abe5-833b5bcb5e6c/dd_5e_ancient_white_dragon_stats.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/14a398f0-cad4-4f9f-8829-fcf94c10a3b6/68616610314.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/02ff80df-5993-4358-9541-7c86843f9dcb/23050084982.pdfIn PDF document text
    • https://636e06b3-920c-4898-b827-ef778bbbc101.filesusr.com/ugd/40512e_b18d3de0331d454eadab3afdfd0fa00c.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/1ac79c6a-b211-42b1-a5c2-f73c2be12d49/tusif.pdfIn PDF document text
    • https://ddf64d59-5240-4154-9987-17dfc28e22c7.filesusr.com/ugd/cec570_40b8fc783d61408499741c1e5c4adf07.pdf?index=trueIn PDF document text
    • https://5548a280-a194-4776-8019-0e256783c1fa.filesusr.com/ugd/f2c1dc_f2b11e8596e3487f897829a5730d0553.pdf?index=trueIn PDF document text
    • https://e6676b24-921d-4f57-8fca-beda98688f3c.filesusr.com/ugd/144d27_907fefb70ba24bc0a6fab54b00f75786.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee85.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEE85 5640 bytes
SHA-256: ff343f62eeaf62b3000f623a5357a0ceb8216473cdbaf32e1dfb761a24f0fda5
font_01_sfnt_off00010192.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10192 11436 bytes
SHA-256: e541fd6d50c0103bde640bc74fd0d57ecbcd57f0a701b42aaa0119413d08ec5c