Malicious PDF — malware analysis report

Static analysis result for SHA-256 aebd6611b3636d89…

MALICIOUS

PDF

86.0 KB Created: 2021-04-26 16:18:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-20
MD5: ee6a8501c7aa12e22e9e65a510408921 SHA-1: 81f14362ff9175a7d78580fb3dafba38e72da596 SHA-256: aebd6611b3636d89bf75fe749534a4d759c133bc928b3bec840b80fafad11845
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains a large number of external links, many pointing to disposable domains, indicating a link farm or SEO manipulation tactic. The ML classifier strongly flagged this PDF as malicious. While no scripts were extracted, the presence of numerous external links suggests a potential for distributing further malicious content or leading users to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9950

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=photoshop+classroom+in+a+book+2020+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4489992/normal_604003bdd6317.pdfIn PDF document text
    • https://muwunijika.weebly.com/uploads/1/3/1/3/131398004/jizigijuzovizo-tasajilagat-riwiwem-xezidot.pdfIn PDF document text
    • https://nifiwaratobiwe.weebly.com/uploads/1/3/5/3/135346776/fdc47ee97e4.pdfIn PDF document text
    • https://kumobavubisu.weebly.com/uploads/1/3/0/7/130775432/gokow.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4393022/normal_60072e889bfb7.pdfIn PDF document text
    • https://cdn.sqhk.co/powurejur/83jhgcm/modern_train_driving_simulator_train_games_2020.pdfIn PDF document text
    • https://nitevugumosu.weebly.com/uploads/1/3/4/5/134526644/42a73a45f41.pdfIn PDF document text
    • https://cdn.sqhk.co/litopozuf/geLjj9e/best_music_player_2020_apk_download.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4450243/normal_5ffcc947120ec.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4380223/normal_5fda4a0bb719b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366337/normal_60472bca79a50.pdfIn PDF document text
    • https://negapisege.weebly.com/uploads/1/3/4/6/134635707/karebemis_nulowu.pdfIn PDF document text
    • https://cdn.sqhk.co/lerapuraroke/jhh6lt4/formula_one_race_usa_2020.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4453906/normal_6030409ba1621.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4385028/normal_6024aa554a138.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4495849/normal_60552ecccce7f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4460950/normal_60684ff22e9f0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4414166/normal_5ff61925f3d16.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/6254ff76-3ed6-4dd7-b83c-deec0ddafec7/central_and_peripheral_routes_to_persuasion_examples.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d098d39e-9aba-4a5b-a7a2-78f44d666f17/viktor_frankl_mans_search_for_meaning_amazon_uk.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ff0ce3e6-fe68-47b1-92de-37e2552d6c99/memories_dreams_reflections_google_books.pdfIn PDF document text
    • https://s3.amazonaws.com/firudegix/naleremagodunifuvuminuvu.pdfIn PDF document text
    • https://s3.amazonaws.com/saziwijaxodav/86946616770.pdfIn PDF document text
    • https://s3.amazonaws.com/besafefaf/duforavuketiv.pdfIn PDF document text
    • https://s3.amazonaws.com/vunizi/asus_p9x79_deluxe_memory_compatibility.pdfIn PDF document text
    • https://s3.amazonaws.com/jevedijadiki/29047877874.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2c134fa8-b3b7-4fd0-9b7c-b94fbcdb061c/disepepu.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f7b7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF7B7 5544 bytes
SHA-256: 508e82a343daccb2f64d2632aa9f17f9e2285dc9f94101647a6c3a17423eeff3
font_01_sfnt_off00010a54.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A54 22668 bytes
SHA-256: 56288e5a779df129894230cb0fe4b66fa6198291c749afc445cb071e69567bac
font_02_sfnt_off00013b87.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13B87 4324 bytes
SHA-256: b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c