Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd6b40f572868682…

MALICIOUS

PDF

158.6 KB Created: 2021-04-17 07:41:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 73628bd97743080d0997a554dc568fcb SHA-1: 77b4cfc7477bf256bd955cc6925d4da538257685 SHA-256: bd6b40f572868682ba1d6a16cd44bb88e42841893820521844cd0681c9786f2c
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically identified as a phishing trojan. It contains numerous embedded URLs, with one prominent URL pointing to a suspicious domain that appears to be part of a link farm designed to redirect users. The document body, though heavily obfuscated, suggests a lure related to digital design and computer architecture, likely to trick users into visiting the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/strik?utm_term=digital+design+and+computer+architecture+risc-v+edition PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4414153/normal_605f55a01de7c.pdfIn PDF document text
    • http://leyloften.online/55951906849cm09p.pdfIn PDF document text
    • https://zekupepub.weebly.com/uploads/1/3/5/9/135992873/rasariro.pdfIn PDF document text
    • https://wekisakalew.weebly.com/uploads/1/3/4/6/134617168/napegefaturusobomifo.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450045/normal_5fd91671d5664.pdfIn PDF document text
    • http://airbin.top/78335298251wzjza.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4371508/normal_5ff53f2f90e72.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420039/normal_604640ba9885b.pdfIn PDF document text
    • http://axecheat1.xyz/batipuzigomekuzajinorine70dm3.pdfIn PDF document text
    • https://lomedalepa.weebly.com/uploads/1/3/4/4/134438906/99c1482d1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4404108/normal_5fd60ba9ad95c.pdfIn PDF document text
    • http://kieverts.xyz/sudimibamedidulevokkjfn3.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://a7563df4-ba19-4d82-a8a0-b2470d957038.filesusr.com/ugd/61f964_f34b0e67fb7447c38ae5bbf8d326e02c.pdf?index=trueIn PDF document text
    • https://ded05c8b-f0d8-42bc-a64b-daa0b63394ca.filesusr.com/ugd/99afdc_9681392a944f429689cc0231b0371dd0.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/461b748d-5251-40e6-8ea5-f18c3c4c2d19/wuzigolewe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a02b38b6-fa82-4d70-9ad6-2d75c52923c3/35756566440.pdfIn PDF document text
    • https://91ca87c2-c493-4616-adaa-fbcec45394e1.filesusr.com/ugd/6116da_3a98d9ececdd47bbb8cf1741775bb152.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/26055b51-e2dd-4d9f-88cd-fbd1aa6a52b3/what_are_the_three_data_gathering_techniques_in_market_research.pdfIn PDF document text
    • https://18cceff7-6d50-42ec-9d85-67184b61345e.filesusr.com/ugd/8c2e83_3f995928014d4cf8b2f23b49338a51df.pdf?index=trueIn PDF document text
    • https://17a6c5a8-0587-4adf-8126-5b439e15a62f.filesusr.com/ugd/54bec1_dd193d679e32467d8ce655558659ee03.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/0437225c-edfd-4152-ada1-1351023d0431/19244032796.pdfIn PDF document text
    • https://4a0f17ac-6ce6-4c05-9546-25c48d39d9f7.filesusr.com/ugd/cd79e3_a4b145a346a6495db0f8deb4cf1025bb.pdf?index=trueIn PDF document text
    • https://c84d532c-3b33-47d6-96aa-4134a1164eb1.filesusr.com/ugd/6d45f6_6407cb3d1a734916accf9d57334d2624.pdf?index=trueIn PDF document text
    • https://f1cb2ec4-a82d-4768-8a06-5236a2db220e.filesusr.com/ugd/a2e20a_cb3179cc38764d08b7a2ee5a32537fec.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/029e63dc-6db0-4b76-ad87-190f3d0cf038/71663165505.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000215b3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x215B3 2828 bytes
SHA-256: eec2311198495a4bc353016469730966835d49679daeed18a98faa9ab15954d4
font_01_sfnt_off00021fbd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x21FBD 5460 bytes
SHA-256: 951cbbf233db24b225aa27fcaf19f5e0b5432d5dc9d47f42a443ec16f77d1e88
font_02_sfnt_off00023228.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x23228 12200 bytes
SHA-256: 4bb9ec5211bbb322d3a78cb8af97d511b9cff4a66d39ecef3a6f8e9bab4c730c
font_03_sfnt_off00025af6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x25AF6 4324 bytes
SHA-256: 1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361