Malicious PDF — malware analysis report

Static analysis result for SHA-256 b535ce764674b8d7…

MALICIOUS

PDF

85.9 KB Created: 2021-03-22 15:27:00 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 63d40708754725d114d85a45777b8c07 SHA-1: 96354fbc67477ee383056a79f37d14dfec7f0aee SHA-256: b535ce764674b8d71fd804cdb987b5b318eed0a62f7b795ad65c759cec81e0fc
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/strik?utm_term=what+does+it+mean+to+dream+about+your+dead+ex+husband PDF link annotation
    • https://xafukulirodut.weebly.com/uploads/1/3/1/3/131379356/cebb295de7c8c2c.pdfIn PDF document text
    • http://vashobereg.com/xenixacs7o9.pdfIn PDF document text
    • https://cdn.sqhk.co/xurazegoba/yU4Sggv/27938845614.pdfIn PDF document text
    • https://cdn.sqhk.co/ruxuvedije/jYidSie/godadutuxori.pdfIn PDF document text
    • http://igme.site/qualitative_analysis_of_lipids_lab_report3ba3n.pdfIn PDF document text
    • http://salonvarna.com/295991744917bhn4.pdfIn PDF document text
    • https://nefipoxitusi.weebly.com/uploads/1/3/0/7/130775115/wukibebilamoku.pdfIn PDF document text
    • https://lopodudox.weebly.com/uploads/1/3/4/3/134339354/gasupuzopizapu.pdfIn PDF document text
    • https://cdn.sqhk.co/zidodovare/hdnPjjC/2_player_fighting_games_free_pc.pdfIn PDF document text
    • http://mexicotop.xyz/21890576778kzdyg.pdfIn PDF document text
    • http://carins.info/wafefozivafuwfslaa.pdfIn PDF document text
    • https://midatapeb.weebly.com/uploads/1/3/1/0/131070166/vadabeva-retomoz-fuxale.pdfIn PDF document text
    • http://dowosateti.iblogger.org/42313791097.pdfIn PDF document text
    • https://jometuke.weebly.com/uploads/1/3/0/8/130874139/0c3258b7d.pdfIn PDF document text
    • https://cdn.sqhk.co/legikowe/libriet/70218803936.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://14864a69-2465-45da-a912-c6f78a3f99b9.filesusr.com/ugd/409ca8_4d86179c9a7f422bacac3aba78034c71.pdf?index=trueIn PDF document text
    • http://nejexapef.rf.gd/61175514454.pdfIn PDF document text
    • https://063758de-fb2f-4258-809e-b727485bfd5a.filesusr.com/ugd/89cda4_024082d9e9ab4a4a8902075f6511d07e.pdf?index=trueIn PDF document text
    • https://a1d1c4ac-cf1d-4c58-861c-45d1188f4b60.filesusr.com/ugd/052f3a_a5e73b9d21c34c5898835465e364a099.pdf?index=trueIn PDF document text
    • http://sujemepis.epizy.com/audre_lorde_books_to_read.pdfIn PDF document text
    • https://e9abb47e-19e5-4ec2-9f3c-2aa4e6f2bf0a.filesusr.com/ugd/92be99_0182beea11674c6a9ef2c4a2e895b060.pdf?index=trueIn PDF document text
    • https://54179944-c6a3-49b3-9462-5d1939b6aff2.filesusr.com/ugd/49f5ef_379c78bf0dd04766b7576c1138a04c4a.pdf?index=trueIn PDF document text
    • https://354df738-7a8c-4643-bdcd-aa58f7c4bd0c.filesusr.com/ugd/69cf62_e6a7d7ab5b05415d92e62b4106cda52d.pdf?index=trueIn PDF document text
    • http://xoxigibutu.epizy.com/95803336846.pdfIn PDF document text
    • https://d7ae471b-a447-437d-81b4-4e603f8679d9.filesusr.com/ugd/0a3240_24e95aacbf814db3802764ce2d318be7.pdf?index=trueIn PDF document text
    • https://d4bcd744-2348-4fe3-9006-05b2fcbd3cbd.filesusr.com/ugd/704566_2e77468e77094bb18a8958f86df74cc3.pdf?index=trueIn PDF document text
    • http://majoxokusixapav.epizy.com/rupuvubogigotidovetij.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010fbc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10FBC 5356 bytes
SHA-256: a1be332e9007cb752cd3b891f333bb593916e62bad36228b7181a6fb14b9987a
font_01_sfnt_off000121d9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x121D9 11576 bytes
SHA-256: d19d66197c3ec3af7b146bd6ce00f536491475280855b2ad0593f7f2079ec336