Malicious PDF — malware analysis report

Static analysis result for SHA-256 b665b54406807c77…

MALICIOUS

PDF

79.6 KB Created: 2021-03-22 07:47:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 6fe02e209542b1d6c840de59005d8cea SHA-1: 75148dab4f9d367cfd2e30bf74c9f94e434e76d2 SHA-256: b665b54406807c77c1ea67df2cb403b3b867b314920e953fd80ad4e390dbd10c
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=lifetime+florham+park+summer+camp PDF link annotation
    • https://bolumuratojepo.weebly.com/uploads/1/3/4/7/134749128/lesaxebitunofulaz.pdfIn PDF document text
    • http://bowuvudofi.scienceontheweb.net/vugaxoxanapebuz.pdfIn PDF document text
    • https://puwibovur.weebly.com/uploads/1/3/4/6/134639487/xepuzavo.pdfIn PDF document text
    • http://xebiniseba.mygamesonline.org/affidavit_form_botswana.pdfIn PDF document text
    • http://xofebuledat.scienceontheweb.net/79041842311.pdfIn PDF document text
    • http://microbestdigitalmeter.xyz/gulomesapedisagipegorazvcct.pdfIn PDF document text
    • https://befuvabesuwab.weebly.com/uploads/1/3/0/7/130740391/279432.pdfIn PDF document text
    • https://gugewixurot.weebly.com/uploads/1/3/4/3/134393699/7004951.pdfIn PDF document text
    • http://wide-mean.top/wezutatokiwok93ue.pdfIn PDF document text
    • https://dejalujufoleto.weebly.com/uploads/1/3/1/3/131378776/mutagejar-dagemirige-vasaribafati.pdfIn PDF document text
    • http://4bochki.ru/new_testament_bible_study_lessons9zl74.pdfIn PDF document text
    • http://dotixomovi.sportsontheweb.net/death_note_ryuk_voice_actor_english.pdfIn PDF document text
    • http://lorakuze.sportsontheweb.net/aparato_tendinoso_de_golgi.pdfIn PDF document text
    • http://blockingscenery.com/angles_in_polygons_worksheet_milliken_publishing_companyxhzga.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://51fd5013-30c4-43d1-89ce-86564632a3b5.filesusr.com/ugd/9f06f8_7ca0fe3f0a8640988ce8218f25f4062e.pdf?index=trueIn PDF document text
    • https://c72a6d71-2fad-4f5a-8b7a-a7c165485bce.filesusr.com/ugd/a4966f_8a04b2ec36e54d2e95cf1931b469ffd0.pdf?index=trueIn PDF document text
    • http://tuparibuju.atwebpages.com/ielts_speaking_samples_answers.pdfIn PDF document text
    • http://rususekobijo.myartsonline.com/navefaxigemutidudum.pdfIn PDF document text
    • https://cb6d8354-940b-4e05-9f1d-0150973ab277.filesusr.com/ugd/882da0_7868a1752a524bf999059ac812d9dea4.pdf?index=trueIn PDF document text
    • https://da89e6ec-52f9-4c28-8de8-447a2e923c0c.filesusr.com/ugd/5e5b2a_b99bcd450eb54715b92887090ed74680.pdf?index=trueIn PDF document text
    • https://07d68bf2-0661-47e2-9ffe-eae068a071af.filesusr.com/ugd/fef806_5a0a7a852ecc47ebb5f441f3c559bfcf.pdf?index=trueIn PDF document text
    • http://nunavaxukozu.onlinewebshop.net/jikapipigomop.pdfIn PDF document text
    • https://2ea9429b-0332-4ee6-bb75-ab9535b56c99.filesusr.com/ugd/e2f7e1_4368aeefacb44a159e8072a1bddfc89e.pdf?index=trueIn PDF document text
    • https://6e7ef639-f89a-4701-86f9-710a836f1183.filesusr.com/ugd/12745a_7ac8b86209074212b1a84d73db4e609e.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fbb8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFBB8 5260 bytes
SHA-256: 373a23141ecae51fc65295a92eaea1847b8862b3af259c6e9475049fdbb1f1c9
font_01_sfnt_off00010d74.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10D74 10300 bytes
SHA-256: 5feb4a18acbca6502dab9af453a5b280f5d3ddc2a7384100a90c734a27e3084c