Malicious PDF — malware analysis report

Static analysis result for SHA-256 bea481fe7bcbbe28…

MALICIOUS

PDF

75.7 KB Created: 2021-06-07 09:58:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: 6c88fed97f914989419804ed3ac79035 SHA-1: 619931619fb260d3d1703d983dfc2946130d3d84 SHA-256: bea481fe7bcbbe28766ca7db47ba6503eeae4b40e3a9dd0b319f0e1960d28418
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm and presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://laborke.ru/pbw?utm_term=the+reader+movie+download+in+hindi+filmyzilla PDF link annotation
    • https://pulolated.weebly.com/uploads/1/3/0/7/130740140/faxadinaw_pivutoja_xabumopom_wimudizala.pdfIn PDF document text
    • https://degumikiw.weebly.com/uploads/1/3/4/7/134724061/xivugazupugekewo.pdfIn PDF document text
    • https://kotevopokevunab.weebly.com/uploads/1/3/4/5/134590751/cfaacac5fe.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4426556/normal_600116d33d77f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369164/normal_6028a414047aa.pdfIn PDF document text
    • https://dezekebewefe.weebly.com/uploads/1/3/4/7/134731304/movugaxatiru.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408871/normal_6054f1dcc95f5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4488806/normal_5fdc407231e24.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413563/normal_6010d5d6d0295.pdfIn PDF document text
    • https://bitojobuf.weebly.com/uploads/1/3/4/8/134892495/jadojedakage-naxiliz.pdfIn PDF document text
    • https://zowadite.weebly.com/uploads/1/3/1/3/131380399/0667114accd2947.pdfIn PDF document text
    • https://zefuriduzowav.weebly.com/uploads/1/3/0/7/130740504/187721.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/5ed809e6-8296-4c6f-886c-85f599d672ed/3_phase_transformer_fault_current_calculation.pdfIn PDF document text
    • http://gosirata.pbworks.com/f/wovumugigolaw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6c45fce8-2ef6-485a-8652-cba7e276f0bd/40613761706.pdfIn PDF document text
    • http://rasetewi.pbworks.com/f/92866706355.pdfIn PDF document text
    • http://zuvevetub.pbworks.com/w/file/fetch/144423258/98681284184.pdfIn PDF document text
    • http://fuxedemama.pbworks.com/f/second_conditional_reading_exercises.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6ea59a12-5a78-4c91-8102-2ad89f688cb3/interview_with_the_vampire_hd_movie_in_hindi_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/078be275-cd04-478c-a5c1-b1564a72efb1/nagelagokegavivatapedesuz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4e2d0732-7940-4494-8268-31466be23212/how_to_wind_a_tempus_fugit_clock.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a6b086d9-f4b1-4c3f-a603-798fe699be05/86870038172.pdfIn PDF document text
    • http://wuranosa.pbworks.com/f/advanced_mechanics_of_materials_and_applied_elasticity_solution_manual.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb02.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB02 5220 bytes
SHA-256: 842896c14709a6cf3ee8a36508a9f59de101a50ff39e75754212121f6bee73c3
font_01_sfnt_off0000fcb8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFCB8 10472 bytes
SHA-256: d1c4ca669c9853a186222f19e36aa3a3a5745d2d12af619e8fddf11a19d0543b