Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f7d0108e09b79cb…

MALICIOUS

PDF

72.6 KB Created: 2021-03-31 21:00:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 29bd4866ad55b5b5a9b3ca3115e3467d SHA-1: 8658df820b30a8c6f4db56c0ba54afa524f4729c SHA-256: 9f7d0108e09b79cba3edbd3dd208c90711a9ab26f3fb1a4d1754f59ea738fee4
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/123?utm_term=traducir+documento+ingles+a+espa%25C3%25B1ol+pdf PDF link annotation
    • http://tilosag.mypressonline.com/47370652750.pdfIn PDF document text
    • http://wezenilokiwuv.iblogger.org/59678321753.pdfIn PDF document text
    • http://zibodotuf.mygamesonline.org/catalogo_avon_campagna_14.pdfIn PDF document text
    • http://vitetiw.getenjoyment.net/wepedizarotiz.pdfIn PDF document text
    • http://bagawixaj.mywebcommunity.org/quais_as_frutas_que_no_contem_carboidratos.pdfIn PDF document text
    • http://xudaxusikuzusu.22web.org/52931155829.pdfIn PDF document text
    • http://vemexulitoko.iblogger.org/computer_network_engineer_salary_in_india.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://wakurenup.epizy.com/importance_of_self_awareness_in_counselling.pdfIn PDF document text
    • http://lavavil.rf.gd/49099961289.pdfIn PDF document text
    • https://044e8d80-c429-4a1f-820d-9b443c65b389.filesusr.com/ugd/53c654_9565f53d0126448aa115e878e5769fee.pdf?index=trueIn PDF document text
    • http://girupesoja.rf.gd/imperia_online_guide.pdfIn PDF document text
    • http://nejovafejasujob.rf.gd/jimmy_fallon_thank_you_notes_sheet_music.pdfIn PDF document text
    • http://rogomore.myartsonline.com/5306836962.pdfIn PDF document text
    • https://dd3528e8-ded0-4753-843e-0d3cb9f542e7.filesusr.com/ugd/4d6844_9bb5eb0a1b3d4e5a875fcf57cb1f5716.pdf?index=trueIn PDF document text
    • http://duzuxaxuba.epizy.com/11648590198.pdfIn PDF document text
    • https://584abdf6-e408-48d3-a53c-4313a8f82471.filesusr.com/ugd/18ee90_aea702c0dcfb4814bd821bcfd49951bf.pdf?index=trueIn PDF document text
    • http://povinadoli.epizy.com/view_formatted_json_in_notepad.pdfIn PDF document text
    • http://nitubak.atwebpages.com/manual_de_brain_gym.pdfIn PDF document text
    • http://xugulirimes.rf.gd/how_to_change_a_heating_element_in_a_candy_tumble_dryer.pdfIn PDF document text
    • http://rekabalukog.rf.gd/ashleigh_jordan.pdfIn PDF document text
    • https://b3df6b87-ca8d-4c26-b815-8c697753997b.filesusr.com/ugd/896a32_e22f3bbf22b541368f21c6063f123711.pdf?index=trueIn PDF document text
    • http://famuxigoram.epizy.com/nuwepebekijodon.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d9b2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD9B2 5636 bytes
SHA-256: af90fbdeb43f0d08d39c4fcecd0196a46b494a981d7e22cbfc72b98eb7df3a13
font_01_sfnt_off0000ec86.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC86 11816 bytes
SHA-256: 3dd71131007cddaa6a9ca704ad667547effe3ead9ff3b92034f1e1da882be71c