Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e129b06b2e68e1f…

MALICIOUS

PDF

81.0 KB Created: 2021-05-12 13:19:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: 009b22841ca581462c04a112a41d9842 SHA-1: 98d81a3d032dff644272caba2295b89980e75191 SHA-256: 9e129b06b2e68e1ff3caec6b6400649f0d9465bcd3c1a388c18a78020ee75d89
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics as malicious, including a critical ClamAV detection and an ML classifier. It contains a large number of external links, suggesting a link farm or phishing attempt. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic indicate an attempt to redirect users to potentially malicious or scam-related websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=masterbuilt+mes+35b+electric+smoker+home+depot PDF link annotation
    • https://cdn.sqhk.co/lexikegije/ao4djbi/cheap_electronic_drum_set_amazon.pdfIn PDF document text
    • https://disumudumoronu.weebly.com/uploads/1/3/1/4/131408153/siremije.pdfIn PDF document text
    • https://cdn.sqhk.co/lepavenujal/ECif5Je/winter_warmer_beer_uk.pdfIn PDF document text
    • https://cdn.sqhk.co/givikofuf/sgfgggf/daderogusatunegidowadod.pdfIn PDF document text
    • https://cdn.sqhk.co/nigulavax/9xAggjU/kopopufot.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4413110/normal_5ff8617328ba7.pdfIn PDF document text
    • https://cdn.sqhk.co/gadewekunel/hehiie3/movies_anywhere_codes_disney.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4405654/normal_5ff3ca554311d.pdfIn PDF document text
    • https://devojakosumu.weebly.com/uploads/1/3/5/3/135314674/84254.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://polekowosegowod.epizy.com/lumudoxofapirozijekaf.pdfIn PDF document text
    • https://c78ffd2e-fc3d-4272-86ca-968d835fb7ad.filesusr.com/ugd/0f9ef0_483a0c8c149c48d3af6669c67362d8c2.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/95c17fff-3fb2-4a41-8ad3-aa467cd27228/mechanical_engineering_technology_-_automotive_product_design_salary.pdfIn PDF document text
    • https://8d67285a-e3c5-4820-bb1a-bb91ce1079a6.filesusr.com/ugd/d54300_8c7888cedd044714b960ad4f86ac0165.pdf?index=trueIn PDF document text
    • https://0df22b04-17ae-4e65-9af8-3af4445b4601.filesusr.com/ugd/71fd01_95c866c1dace437cb7b1772e4caed0e5.pdf?index=trueIn PDF document text
    • https://f19d2187-ce67-4d04-8798-eef694565169.filesusr.com/ugd/bd4746_cb4c5fd2ead34b3a973d543714189d62.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/64cd53b8-592c-4f6f-9e08-dc5bb5e14357/kudomino.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ba0f97d5-9844-4476-bc0e-1feaa2df41c9/13817882395.pdfIn PDF document text
    • http://gogolozumer.epizy.com/fedenevumotito.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4c264996-1f4f-49e0-a2f8-fea49c10cfe4/cdma_workshop_2.7_full_descargar.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4e97eee7-32cf-4ea4-9d68-f56716d325f7/84028585223.pdfIn PDF document text
    • https://183cab0c-2e2b-44e6-b55a-0f82cb58e578.filesusr.com/ugd/133137_dee8e72ef5ce46ff854426e204c6015d.pdf?index=trueIn PDF document text
    • http://konevimojo.epizy.com/baahubali_2_audio_naa_songs.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb50.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFB50 5808 bytes
SHA-256: 1abfbc16ed33f30343cf204906cedf0df092fb3ddf1da888ed1be609ca84985e
font_01_sfnt_off00010ef6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10EF6 11576 bytes
SHA-256: 119d85546c710cab24d496ca13c5de7210703a32dc6ec16b3d7fa034dfda6520