Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3669daffbd0b7af…

MALICIOUS

PDF

75.6 KB Created: 2021-02-22 08:49:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e2492752ea81ac312876c988b76c6c5b SHA-1: 781633bd5e0c7a89b79378912aab3c76639e2ac0 SHA-256: b3669daffbd0b7af7b6646b51e6a616c48639793d98acbde29739ba620de7581
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains a large number of external links, many pointing to disposable domains, indicating a link farm or SEO manipulation tactic. The ML classifier strongly flagged this PDF as malicious. While no scripts were extracted, the sheer volume of suspicious external links suggests the document is designed to redirect users to potentially harmful content or further stages of an attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/strik?utm_term=kathie+lee+gifford+husband+today+show
    • http://antonioit.space/christmas_holly_leaves_templatess8t9e.pdf
    • https://tedofejufada.weebly.com/uploads/1/3/0/7/130775935/pinitof.pdf
    • http://rankingcoach-seo.com/2712439255zcb4e.pdf
    • http://instapodarok365.site/hua_bechain_pehli_baar_song_audiocdh79.pdf
    • https://vavaxurose.weebly.com/uploads/1/3/0/7/130775274/pavujaxesowelo-lefowurar.pdf
    • https://nibonitet.weebly.com/uploads/1/3/0/7/130776737/02f55e7ef.pdf
    • https://gapidekejoz.weebly.com/uploads/1/3/4/8/134876705/6636648.pdf
    • http://natur-bio.space/bonobobofexctv4s.pdf
    • https://fusodozot.weebly.com/uploads/1/3/4/0/134096428/a3c2fc0a4cc232.pdf
    • http://nicechange.space/best_oblivion_mods_guide5vw3o.pdf
    • http://insurancesouk.com/48693992675k8dsa.pdf
    • https://lemefiware.weebly.com/uploads/1/3/4/0/134017231/0072f9d66419e.pdf
    • https://rovonowevon.weebly.com/uploads/1/3/6/0/136051941/9213340.pdf
    • https://vulodimov.weebly.com/uploads/1/3/4/8/134880101/perizusidukab.pdf
    • https://pojojozujivalim.weebly.com/uploads/1/3/1/1/131164399/8720732.pdf
    • http://mkuu.club/counter_strike_1.6_cd_key_ifresihmg6q.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/jasadavebaga/ieee_format_for_project_report.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8ad.bin
14aa7735238a3340a021404344c123f656fc48bb8f5c70c6aa33770c56c0cabc
pdf-font-stream PDF embedded font (sfnt) at offset 0xE8AD 5472 bytes
font_01_sfnt_off0000fb60.bin
615b25d0cdcdbe5c378e2538f841c9a604b598925024c647fd77b359af7aef80
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB60 11232 bytes