Malicious PDF — malware analysis report

Static analysis result for SHA-256 bfe7fb5f26247076…

MALICIOUS

PDF

154.3 KB Created: 2021-03-17 00:03:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 2656bae84e22eb189ae544d6add51237 SHA-1: 9146e6f993031461968b37e730a8a2a0c92027c1 SHA-256: bfe7fb5f262470767e3b0bcdde73e5083a3d613d56b9c60cf89f6c6a289f66e9
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/wix?keyword=nuclear+test+ban+treaty+1963+impact PDF link annotation
    • https://cdn.sqhk.co/zizenozi/gdGiihb/common_cold_pathogenesis_slideshare.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4489844/normal_601a1fd8ecaa2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4384159/normal_60333e15804b1.pdfIn PDF document text
    • https://fitijozis.weebly.com/uploads/1/3/4/3/134372299/pulaxoxaxob.pdfIn PDF document text
    • https://cdn.sqhk.co/rodoruwuwab/NXPKGjc/26502976932.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4463807/normal_5fecb4f85e3ce.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451025/normal_603f4e9ff1c78.pdfIn PDF document text
    • https://mugepofenabozu.weebly.com/uploads/1/3/5/9/135970449/bazexokirisol-zazonet-wizefuki-tonagirep.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4378641/normal_6031fa4548f62.pdfIn PDF document text
    • https://daxajofu.weebly.com/uploads/1/3/0/7/130740026/vuxipup.pdfIn PDF document text
    • http://wedagumo.iblogger.org/panasonic_kx-t7731-b_user_manual.pdfIn PDF document text
    • https://dakusarifupufa.weebly.com/uploads/1/3/3/9/133997242/8934971.pdfIn PDF document text
    • https://cdn.sqhk.co/puzadowoke/dlzuPyr/40009587602.pdfIn PDF document text
    • https://sizizobit.weebly.com/uploads/1/3/5/3/135389707/popujole.pdfIn PDF document text
    • https://cdn.sqhk.co/tusadopovet/idajfhb/free_brain_games_for_seniors_aarp.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4483097/normal_5fed3ccfe97e6.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4479240/normal_5fe6ef3728586.pdfIn PDF document text
    • https://cdn.sqhk.co/xasakeza/r6e8vgg/country_music_artists_2019_female.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/5e152e03-50af-452f-bfc1-4035d3fe544f/84056390038.pdfIn PDF document text
    • http://dubabin.rf.gd/28027406274.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7ea849f5-281c-4731-9841-32a1adbf9c37/summary_of_a_confederacy_of_dunces.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/88a26820-2d19-4dcc-861b-3e51ce6ea2ea/dosatunilawebak.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000220c3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x220C3 5816 bytes
SHA-256: 331c518bd91ed73796bddbeb6844aa1e9ce9be49be3717e42c4e6b88ecf93b78
font_01_sfnt_off00023482.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x23482 11712 bytes
SHA-256: e08db2d943f6a8fe8f9fb62985fb3d8adf9c450e04f9ef43c9800c5d39fa0a09