Malicious PDF — malware analysis report

Static analysis result for SHA-256 a000ece132163c9c…

MALICIOUS

PDF

75.7 KB Created: 2021-04-07 03:46:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: bf330110bf8eacbe4a5eacc21aaff4ac SHA-1: 90c8fdc57cc0db9218a0ff0954186b6c42497f64 SHA-256: a000ece132163c9c2e5be06e9fe49be71f907acb2b2b99c9a9c74d9123c4a1d5
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/123?utm_term=definicion+de+paciente+agonico+pdf PDF link annotation
    • http://drive4mclaneeffingham.com/pearson_texas_algebra_2_form_k_answerst1i7e.pdfIn PDF document text
    • http://winfreeiphone.xyz/at_t_u_verse_tv_u200_channelszyjji.pdfIn PDF document text
    • http://fastdonwload.space/shirt_size_guide_menslgjxd.pdfIn PDF document text
    • http://arevakar-travel.com/warranty_deed_minnesota_formu17hy.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://ac263381-fdad-4fda-ae78-6df6d71032d6.filesusr.com/ugd/25c42e_b25ab6710e9c4470962a87d28dd0d1e3.pdf?index=trueIn PDF document text
    • https://01c4c9a3-ee74-4db9-a65d-799443b8dbf1.filesusr.com/ugd/a64c8c_0b2ad9fc1a3f4d6cac9950368e6afb65.pdf?index=trueIn PDF document text
    • https://28481333-1ef2-46fb-8ebf-d56c3f24acbc.filesusr.com/ugd/314c35_4cb3cdb91db54bc3bdc1f19513046b66.pdf?index=trueIn PDF document text
    • https://8767aa75-4bd5-48c0-94ca-24e983238001.filesusr.com/ugd/debdc1_324f20a795df4fecaceafcdafcc51899.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/04c2417c-15c7-47cb-84d5-071960a94095/tuvataxasogawetamifuju.pdfIn PDF document text
    • https://6eed613e-cbae-405e-b458-9655ef9033f8.filesusr.com/ugd/e4f6f0_9fe264ccc09f48db83d021fa5c93f9a6.pdf?index=trueIn PDF document text
    • https://57933e30-1e86-4cbe-ad2b-777cb72f9932.filesusr.com/ugd/235f1a_341377fa80b24bac8c7e3bbf67bc6def.pdf?index=trueIn PDF document text
    • https://6e37e838-c278-4d46-baa9-25b8497af200.filesusr.com/ugd/fbcb80_d4346e4346ae4344b4f1859e4e7f036e.pdf?index=trueIn PDF document text
    • https://9c43cb74-45e3-47de-9527-fda2e8336169.filesusr.com/ugd/af0aa9_eb70e65d268f465eb249834f0ad1c568.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/820e04e9-928d-411c-aa8f-4fa1475bf8c5/the_girl_with_the_dragon_tattoo_novel_series.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fc25f19f-9012-4bf6-a52d-3d5dbcba75a3/the_nutcracker_and_the_mouse_king_quotes.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d4409034-6586-4517-b512-0398f837b7d3/luwob.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/412645b0-9969-486f-b137-f1628cc3c4a0/are_sonic_mozzarella_sticks_keto.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e169bc7c-1805-410f-b747-4fd8e9adc52c/30021654075.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/67acd208-643a-43a2-b61b-e9d8264320ae/litimerudugazurabolegel.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8dc790fd-5855-4898-a81d-0ffc735643af/clark_forklift_dealer_wichita_ks.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e59c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE59C 5016 bytes
SHA-256: 97923662d187955abf132916b477a69f5a583fed10b52b8d5cb26bebed2bb338
font_01_sfnt_off0000f6d4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF6D4 12572 bytes
SHA-256: 8042240e8a41ec8d166839320016127867217d6840d9b768958123c52db2ec89