Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b0afbc6adc7d0c1…

MALICIOUS

PDF

77.4 KB Created: 2021-03-12 07:33:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 3773643595bacf2d268276d75117462a SHA-1: b72fdccc7f458369ef578a213db8d241ef9156de SHA-256: 9b0afbc6adc7d0c1a5ccc8005d0a2fe92d5bbeec4ac714e248bacd0b0d655f02
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/award?keyword=celiac+disease+book+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4486061/normal_601e11ed92fc4.pdfIn PDF document text
    • https://cdn.sqhk.co/sifilefu/65gdRhh/download_game_mod_join_clash_3d.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4496824/normal_5fe4f7e87eb81.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4445866/normal_5ff311b214df6.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4368238/normal_5fdec8b1a6657.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4391305/normal_6003546febe04.pdfIn PDF document text
    • https://cdn.sqhk.co/lijusute/hibicZ8/41055812657.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4426687/normal_603e6e778975b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369911/normal_5fd76e29a6eba.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4385612/normal_5fcea92c138f1.pdfIn PDF document text
    • https://cdn.sqhk.co/vejuwozigef/cjhggii/65731007793.pdfIn PDF document text
    • http://bozidik.22web.org/fafotubewuboladutu.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4495988/normal_60263d9ad16ba.pdfIn PDF document text
    • https://cdn.sqhk.co/rexukewanej/hjfc3ii/chikungunya_disease_caused_by.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4387240/normal_6006717c2cd49.pdfIn PDF document text
    • http://degapituva.iblogger.org/estimation_and_costing_in_civil_engineering_ebook.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4385217/normal_5fd0e29221462.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4378848/normal_5fd7ca857c02e.pdfIn PDF document text
    • https://cdn.sqhk.co/luwiwaduna/ii1ha1p/biterelo.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://mirapate.rf.gd/ielts_practice_test_2_reading_answers.pdfIn PDF document text
    • https://c18d9829-3add-4afa-bc87-35007fe3998a.filesusr.com/ugd/70c1ec_68f2f1d665574c5f99bb4bcc64425fe1.pdf?index=trueIn PDF document text
    • https://17851959-1482-4b49-8222-7b7b0c628459.filesusr.com/ugd/3cb679_4fef1f48cb6f4b84993dda5797f915df.pdf?index=trueIn PDF document text
    • http://zekaroja.epizy.com/how_much_do_housekeepers_earn.pdfIn PDF document text
    • http://vomozenofeke.epizy.com/benzimidazole_drugs.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f276.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF276 5164 bytes
SHA-256: 3a0fb9f2fb62ce7cce72ae7d66c33e5d5973ed4c374b6da5df24152b77cba80b
font_01_sfnt_off00010413.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10413 10460 bytes
SHA-256: 097ea3bc398ee72abb92549a01d0708415253e9334c685e1a3eec745ecf0b533