Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3975c5b0cafff3f…

MALICIOUS

PDF

101.3 KB Created: 2021-05-25 16:45:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: bb79ecc3bf224a4e49883307be03e9f4 SHA-1: 9f84c4de4ed7ffde448c91421d8d0c91e15fc14e SHA-256: b3975c5b0cafff3f7426f8243d6e32cb6a92e01347b20c6a7d7584fda4a7d44c
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=pubg+english+song+download+mp3+pagalworld PDF link annotation
    • https://zomereke.weebly.com/uploads/1/3/5/3/135397468/lenubuwojuf.pdfIn PDF document text
    • https://kumevilowe.weebly.com/uploads/1/3/4/5/134598600/6907357.pdfIn PDF document text
    • https://rupebadik.weebly.com/uploads/1/3/4/4/134465272/2614444.pdfIn PDF document text
    • https://rijivujebevobog.weebly.com/uploads/1/3/4/4/134488471/vokuwidot.pdfIn PDF document text
    • https://sovawetozinunur.weebly.com/uploads/1/3/1/4/131407226/vorozigapakizurur.pdfIn PDF document text
    • https://bolowarokarov.weebly.com/uploads/1/3/4/3/134349384/botib_tavani_denosubunenil_sabevowo.pdfIn PDF document text
    • https://jipuziloki.weebly.com/uploads/1/3/2/6/132695969/rozowe.pdfIn PDF document text
    • https://panikudar.weebly.com/uploads/1/3/1/4/131437701/c14226c1c0.pdfIn PDF document text
    • https://wazivako.weebly.com/uploads/1/3/0/9/130969042/niruzudokodalesot.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4446016/normal_606a35a65f15b.pdfIn PDF document text
    • https://vagibize.weebly.com/uploads/1/3/4/6/134618654/bidezig.pdfIn PDF document text
    • https://jokikisiva.weebly.com/uploads/1/3/0/8/130873994/duvedejonakamaga.pdfIn PDF document text
    • https://pekumovulimezel.weebly.com/uploads/1/3/4/3/134363026/4724789.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4484632/normal_6027852e18704.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4402933/normal_6046569525b20.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://uploads.strikinglycdn.com/files/c3f52282-8d04-4e52-89d3-c2078ca5c490/nogosimafekovilubikun.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/03cf6abc-ad0b-4c49-8d73-140853815559/rugujoxozapotolat.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/69828444-308e-4f01-bff9-1c7a63fd4506/gakipagezagipikedadi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f820.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF820 5772 bytes
SHA-256: ff124dc0aa097fb5a7d2680f34298ca74773b7a4c5f1c2397ebd8ca963722609
font_01_sfnt_off00010ba3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10BA3 3000 bytes
SHA-256: 04b6156129c2a6e1cb4c5edc51dc6b76be4baf2dca460daa9ba69311610bf071
font_02_sfnt_off000117e5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x117E5 6380 bytes
SHA-256: d4b08c5c6664002532aaf419af752871f9991d8cc9e2252cbd1defc0a0159100
font_03_sfnt_off00012a2f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12A2F 11844 bytes
SHA-256: d5c85ace40449a42323f3718232f6a7986b03b8a3985af78e36e6dbeee9b6468
font_04_sfnt_off000152d5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x152D5 16488 bytes
SHA-256: f83426e73af4f6c9d964917a314c40ff9077cdd6f6f6566295a856fb89bf9b17
font_05_sfnt_off00016937.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16937 8852 bytes
SHA-256: 34d5e2689259054eb782df96b9d5a165712348aab48294d18a1702ea0026b320