Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c67aa384608cb42…

MALICIOUS

PDF

77.9 KB Created: 2021-05-29 14:28:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 90603f190e2766fc8b1d8f2c2a407a4e SHA-1: 82268638520ab3d6519a125831f82d4340bfed0e SHA-256: 9c67aa384608cb42da8e3210b17d8b1de9f6d208230b4aa63eecd648c045ccde
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9956

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/123?utm_term=automatic+call+recorder+pro+free++app PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4459177/normal_606c47939f39a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370530/normal_6037c3270e90a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4412902/normal_5ff3c1d0c1f80.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4411229/normal_5fcc82cc6fdf6.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4446636/normal_6055c122015ed.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4497369/normal_601241de57a5a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4501659/normal_6027b6cc4d143.pdfIn PDF document text
    • https://pewoguliburutoj.weebly.com/uploads/1/3/4/2/134234653/medaxowogetoj.pdfIn PDF document text
    • https://kaxobemux.weebly.com/uploads/1/3/4/6/134676595/1c44b06.pdfIn PDF document text
    • https://folumenudi.weebly.com/uploads/1/3/2/6/132681426/mafite.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450248/normal_601db529a2355.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4460723/normal_5ff2acc0876f8.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451374/normal_604e1710285fc.pdfIn PDF document text
    • https://gitujibexilen.weebly.com/uploads/1/3/1/4/131406430/4759691.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/444ecf88-8ac1-499d-8c8e-3f0b47ced60c/zurupipoxobol.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b603d781-2be6-40b9-8edb-47ad0fda8105/50786168234.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6ff7a0bd-4335-4ddf-ae1a-e8f4e4bbc9e8/11528503019.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b263ed87-ff2f-49b7-95c2-53eefc4f9334/54557740164.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/add74324-a028-4d13-8fb9-9e519e60a5d8/ralufamoxugimer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3aed3885-d89f-42de-a363-94c45cfe75ef/how_to_put_a_toro_zero_turn_mower_in_neutral.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/590820a1-408b-4103-92d1-c6bf337665ce/sowakojikijawaxunos.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/78db28cc-d50f-450b-8220-4f6f1bf641cf/86586055570.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f0447870-038d-45e0-b103-dcbaaaf1ad13/retevujuzokuwesotojixotu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2ad6ea99-db16-4d48-97ce-89708b61696b/xepefofesak.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3002ddc8-a316-4523-baa7-39f3f7285b15/53891508888.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ba1cbe77-2408-42d4-85ab-80a82002a709/how_to_assemble_a_spalding_portable_basketball_hoop.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e663.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE663 5112 bytes
SHA-256: 56d43cb0e92c8b966764256a8efad56f326a7666a69b8957968fd151a0316e19
font_01_sfnt_off0000f7af.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF7AF 21972 bytes
SHA-256: fc261fb16bf5040492548cc1682965181ee97c8650eebd3c4d74d3cf4a0681b5