Malicious PDF — malware analysis report

Static analysis result for SHA-256 b20e119d4c898054…

MALICIOUS

PDF

89.2 KB Created: 2021-03-15 16:34:00 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: c73ef36e543bec38709056033229ecc5 SHA-1: 16e20b4a645cf9842bff7c801e3e0c87ac5b282f SHA-256: b20e119d4c8980548402edb502bdfac1df53369df3b72b50528d9ff238ea25cd
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/award?keyword=essential+actionscript+3.+0+pdf PDF link annotation
    • http://timinome.getenjoyment.net/govejapar.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4491445/normal_601b62ad0642d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4458623/normal_602c6ca5a0f3e.pdfIn PDF document text
    • https://cdn.sqhk.co/kimefutif/cTIhgRf/66426650541.pdfIn PDF document text
    • https://cdn.sqhk.co/waderapal/x20Ficb/rimagelokupolovunub.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368752/normal_60171fe560030.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4403685/normal_603673ce11115.pdfIn PDF document text
    • https://cdn.sqhk.co/jipogidara/ghjcd7f/park_management_courses_online.pdfIn PDF document text
    • https://cdn.sqhk.co/kadunila/icPnQjg/cobb_theatres_tyrone_mall.pdfIn PDF document text
    • http://dotixomovi.sportsontheweb.net/local_anesthesia_composition.pdfIn PDF document text
    • http://lamisorosasam.mywebcommunity.org/25265037045.pdfIn PDF document text
    • http://rexonina.medianewsonline.com/goal_setting_worksheet_for_students.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4494883/normal_60160508aece8.pdfIn PDF document text
    • https://cdn.sqhk.co/tusadopovet/hgiolgi/sudowarojavefesolosebezo.pdfIn PDF document text
    • http://kogowetek.getenjoyment.net/kawiribekobajos.pdfIn PDF document text
    • http://dududuw.mypressonline.com/96777740414.pdfIn PDF document text
    • http://bewewafip.scienceontheweb.net/terugixewuvovok.pdfIn PDF document text
    • http://fudazozotakaxal.mywebcommunity.org/23336933065.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jajuzasalikirut/jujanowovuwalaboko.pdfIn PDF document text
    • https://s3.amazonaws.com/gupawupigawono/autonics_ct6s-_1p4.pdfIn PDF document text
    • https://s3.amazonaws.com/dusubonifu/channa_mereya_full_movie_free_filmywap.pdfIn PDF document text
    • https://s3.amazonaws.com/bokofapig/momentane_nderungsrate_ohne_formel.pdfIn PDF document text
    • http://tonavisuma.onlinewebshop.net/muxonudivovupinotapa.pdfIn PDF document text
    • https://s3.amazonaws.com/guwutivupudutu/abies_fraseri_fact_sheet.pdfIn PDF document text
    • http://kegigija.atwebpages.com/gst_amendment_for_nov_2020_ca_final.pdfIn PDF document text
    • http://gegetebipa.atwebpages.com/argirol_colirio.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011d5c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11D5C 5444 bytes
SHA-256: cd8102056d4148f26180156103b57c6da5b94a7cc4890aa175f6bddc84d519bd
font_01_sfnt_off00012ff1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12FF1 11704 bytes
SHA-256: 53062753466038db044381f5f0af034b82ac8451d060eeaf836474371d70dc35