Malicious PDF — malware analysis report

Static analysis result for SHA-256 c39f38da775e2371…

MALICIOUS

PDF

107.3 KB Created: 2021-03-22 18:42:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 470b08d6542f0c5ce5525a62b3f5278a SHA-1: 568c927c4e56d55065d8f5df669d3d5d41f2ae93 SHA-256: c39f38da775e2371fa36206d1f6f7dd8835f6af8692f4abe231b91650e5fe1d2
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm and presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/wix?keyword=cub+cadet+cc30+operators+manual PDF link annotation
    • http://tonevagewalilu.medianewsonline.com/al_quran_terjemahan_free_download.pdfIn PDF document text
    • http://mantenancie.com/minecraft_for_mac_os_x_10._7ma20c.pdfIn PDF document text
    • http://microbladingcertificationdfw.org/pujosolosufilavusijotb0mp.pdfIn PDF document text
    • http://lejifip.sportsontheweb.net/jikoxuwitajova.pdfIn PDF document text
    • http://dowotezovemalo.mygamesonline.org/bamupeparidaraxugutotone.pdfIn PDF document text
    • http://pushbiz.fun/179568572902ul70.pdfIn PDF document text
    • http://whalesqpa.fun/vinewirugiwts8c.pdfIn PDF document text
    • http://veruvipavopa.getenjoyment.net/ruratebuxawezud.pdfIn PDF document text
    • http://selomankap.space/heart_gold_ring_collectionfvkol.pdfIn PDF document text
    • http://quinzsy-studio.design/gigabyte_kaby_lake_overclocking_guide5iyg7.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/45689117-b236-452c-a67e-a2eb6e506909/20_questions_to_make_a_guy_fall_in_love_with_you.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/825fcfe5-95c2-4bd9-8371-afc1aa54b779/xijetipiparuxuwaxawowugoz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/56938763-c0f8-4b18-b184-449d643463b6/what_is_a_good_score_on_the_mensa_practice_test.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/af32d2df-e70d-4d47-8307-7e2029a679c9/36135411661.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3ac8cbd6-e02b-4900-8192-285518440ee8/stephen_kings_it_movie_1986.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a45182f1-f8f9-48a3-97ff-be92731e0741/how_to_unjam_a_porter_cable_finish_nailer.pdfIn PDF document text
    • http://famomijis.onlinewebshop.net/free_converter_to_word_file.pdfIn PDF document text
    • https://e26976e3-f089-44cc-a2a6-54bcc6cae308.filesusr.com/ugd/0df15e_868e495db02e4308a824b393f0b1b400.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/b7fcf7a9-2ea4-4043-8fde-e85d8662235e/quicken_printer_error_code_30.pdfIn PDF document text
    • https://01dc7cc6-b8ed-446e-8cc8-1ad78882ed38.filesusr.com/ugd/e23fbb_e91ea1ddaeaf411bab963cafad656d94.pdf?index=trueIn PDF document text
    • https://d0bf7e8b-5449-41c0-93e9-161603c0719f.filesusr.com/ugd/197ed4_ed91f23bc72d4df99aec90d35fdb205e.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001652d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1652D 5572 bytes
SHA-256: c11e883883490f3f03c1d3009efd7518c82bc1ad078e7b85d878c4c3be1137ae
font_01_sfnt_off000177f1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x177F1 11008 bytes
SHA-256: e8761f83783a461b4f7e3a5d27267cdcbd9205d80a78bcedbdf580dc304b7816