Malicious PDF — malware analysis report

Static analysis result for SHA-256 bb2b25c65ee03d58…

MALICIOUS

PDF

75.2 KB Created: 2020-12-14 22:31:13 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-14
MD5: c646cd0eeb3655e5463ed3f0e37acf31 SHA-1: be61d1e20027eff1ed0b9c5fea48c100fadc6e6b SHA-256: bb2b25c65ee03d58eb5e2c91049e63d62af5132c30d3c1a66241f86b10c3dda5
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file is a PDF that contains a large number of external links, many of which are to other PDFs, suggesting a link farm or phishing attempt. ClamAV detected it as Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0, and an ML classifier also flagged it as malicious. The document body, though heavily obfuscated, contains text related to 'color matching worksheets for kindergarten', indicating a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/aws?utm_term=color+matching+worksheets+for+kindergarten PDF link annotation
    • https://kawijidaxo.weebly.com/uploads/1/3/4/8/134891868/kubemevibelube.pdfIn PDF document text
    • https://wimelavejitovuv.weebly.com/uploads/1/3/4/5/134597731/nobejakasopozapuz.pdfIn PDF document text
    • https://bubixoduxufito.weebly.com/uploads/1/3/1/0/131070588/adc52752fec1d35.pdfIn PDF document text
    • https://kirimanadawa.weebly.com/uploads/1/3/4/3/134383910/4f5e23.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://static1.squarespace.com/static/5fc370a42cf09257bd7c0e07/t/5fc487716457125654ccb84b/1606715250280/pojodelivepamujigokufaj.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc77ace717a0f60c4039b47/t/5fcfe7371ce5cc3a1103a765/1607460664365/89449742125.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc5cbbe104edf1d77a2c1c8/t/5fcb4b848dcc5603bef1dc1f/1607158662726/zukovenuk.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc5d30b7848ba205d3a93a9/t/5fd601a15b1f6f7539cccfba/1607860642177/xitoralibewegofinagir.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7f44fdac-30b8-411c-ad6b-da5921a5e7a1/75803949732.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc77c63f59f035d0ccd600e/t/5fce0f9e74a40730fbbfa802/1607339935462/93609398520.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc64bd1be9b6939512f98cc/t/5fc702dba3696915e21a4154/1606877917680/hangman_movie_2017_ending_explained.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c2c86b28-19dc-4661-82ff-d289ab1289b8/warrior_goddess_training_workbook.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc144dc68612547ed60a5eb/t/5fd1b15eac13f65f6612288c/1607577951747/zinefixev.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc1beaab8467722f1da3b48/t/5fc5e6034f98375720aaf242/1606804996189/divijobasotugalemolozev.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000db0d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDB0D 5404 bytes
SHA-256: a8aaaf8cd5fdddc36c9dff88c5511bdb13d60f3d10daad9cc0bdfef48345fe29
font_01_sfnt_off0000ed52.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED52 10560 bytes
SHA-256: 63e82a4d747e24a60e2d1b3b6e1d87a3596f0ddaba006d0914c7495f5f11b8a2
font_02_sfnt_off00011132.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11132 4324 bytes
SHA-256: d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378