Malicious PDF — malware analysis report

Static analysis result for SHA-256 c28e6e960395d1ec…

MALICIOUS

PDF

88.3 KB Created: 2021-06-03 18:16:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: 240604ba81acb807c130b768107520da SHA-1: 54a6cd7beb6121ba8f17c157cb9b0c6f841c8638 SHA-256: c28e6e960395d1ec3e21feb04e48ff36afd1d40a137f3661174b7e658aaa5462
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier. It contains a large number of external links, many pointing to disposable hosting, suggesting a link farm or phishing operation. The primary external URL observed is https://crewmak.ru/pbw?utm_term=how+long+to+study+for+teas+exam, which is likely part of the malicious infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crewmak.ru/pbw?utm_term=how+long+to+study+for+teas+exam PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4495262/normal_5fffdf4787e0c.pdfIn PDF document text
    • https://nonufovoda.weebly.com/uploads/1/3/0/7/130775853/bezalizigogexiwazi.pdfIn PDF document text
    • https://viluvaxev.weebly.com/uploads/1/3/5/9/135974466/4002778.pdfIn PDF document text
    • https://joxalazugadono.weebly.com/uploads/1/3/1/4/131437099/logopu.pdfIn PDF document text
    • https://pomegikupabuvad.weebly.com/uploads/1/3/4/1/134133078/5005512.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393632/normal_60153a22df86c.pdfIn PDF document text
    • https://mefarixikokupa.weebly.com/uploads/1/3/4/7/134759110/rapizutero-vorijeg.pdfIn PDF document text
    • https://xanifinutevafux.weebly.com/uploads/1/3/0/7/130739814/13581b6e337b58.pdfIn PDF document text
    • https://kusavavatixe.weebly.com/uploads/1/3/4/8/134878613/7014992.pdfIn PDF document text
    • https://nudaduxovusupin.weebly.com/uploads/1/3/4/3/134337963/vetivipu-dejuxa-lepafekijo.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/35195ccf-ac70-49b7-993d-0ffdc5ce8467/conair_facial_steamer_walmart_canada.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e0430a28-5fb8-4ff3-846d-97664bcf0164/voodoo_labs_pedal_power_2_dimensions.pdfIn PDF document text
    • http://pupowivala.pbworks.com/w/file/fetch/144565389/xunurarokinobunorib.pdfIn PDF document text
    • http://numefen.pbworks.com/w/file/fetch/144539679/how_much_does_a_internal_auditor_make_in_sa.pdfIn PDF document text
    • http://negaboxa.pbworks.com/w/file/fetch/144478248/who_moved_my.cheese_summary.pdfIn PDF document text
    • http://gatasulupu.pbworks.com/w/file/fetch/144422229/zibekomalutisujo.pdfIn PDF document text
    • http://wotasaful.pbworks.com/f/ninosarazedupufokinuzava.pdfIn PDF document text
    • http://gamaxidad.pbworks.com/w/file/fetch/144535794/boxegukubumeniluw.pdfIn PDF document text
    • http://damopijos.pbworks.com/w/file/fetch/144499341/how_to_hang_ikea_besta_tv_unit.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011db5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11DB5 5448 bytes
SHA-256: 5ccd50931bf5de287e14b8778095fe6cf7cef05f4f6b5c99ee7b0b6c267b82fb
font_01_sfnt_off0001304c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1304C 10468 bytes
SHA-256: 39816858d801032dcf9a857dae20614e84e9ad489f46149b97507c67aa2aa719