Malicious PDF — malware analysis report

Static analysis result for SHA-256 c63c93dc86561e2d…

MALICIOUS

PDF

74.4 KB Created: 2021-03-07 23:26:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-07
MD5: d6a51339698ef326a7fe70f767b169b9 SHA-1: f3f025fc492c681bff420ff4d53baa80c76084da SHA-256: c63c93dc86561e2dfc8f8647e45d6274d71dbd772492583910a9b24778d98fa1
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a significant number of external links, many pointing to disposable hosting, suggesting a link farm or SEO manipulation tactic. The embedded URLs likely serve to redirect users to malicious sites for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9984

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=da+bomb+combat+stem PDF link annotation
    • http://siankaanmexico.com/vumifiloforologupete2rn9l.pdfIn PDF document text
    • http://smartcreditscore.info/eigenfactor_journal_citation_reportss6vze.pdfIn PDF document text
    • https://lalojitewimagix.weebly.com/uploads/1/3/5/3/135304200/b9dd5cdf.pdfIn PDF document text
    • https://lunafegosewexik.weebly.com/uploads/1/3/5/3/135351611/wogogolodakogupeme.pdfIn PDF document text
    • http://zesaguzijor.mypressonline.com/pride_and_prejudice_full_book_read_online.pdfIn PDF document text
    • https://cdn.sqhk.co/nufesewepi/jbgdRZB/nda_exam_2020_answer_key_set_d.pdfIn PDF document text
    • https://cdn.sqhk.co/runetonorox/NhbdAjd/pacsun_jeans_review.pdfIn PDF document text
    • http://grandov.pro/lulazexetovejavofokipulorn6xv3.pdfIn PDF document text
    • http://fasekafalig.scienceontheweb.net/57021293177.pdfIn PDF document text
    • http://modernstyle.pro/alice_walker_everyday_use_character_analysisba902.pdfIn PDF document text
    • http://lapiwudoxavov.scienceontheweb.net/why_wont_my_flip_video_camera_turn_on.pdfIn PDF document text
    • http://janafan.scienceontheweb.net/7803945418.pdfIn PDF document text
    • https://nisaxiguxizi.weebly.com/uploads/1/3/5/3/135306566/7c51c062d.pdfIn PDF document text
    • https://setuwome.weebly.com/uploads/1/3/0/8/130874340/dcca5b97.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/ed5083ec-140b-4519-a04e-3f7cf363b0b0/how_to_program_a_ge_universal_remote_cl3.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a8ccb21d-ff40-4c59-863f-2d6aa89707bd/how_to_insulate_lay_z_spa_pump.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c9ab7c84-2b7c-4659-bf84-5d291387482c/how_often_to_change_transmission_fluid_vw_passat.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7e709262-8135-44be-ba2a-0a677602d2a4/dekimedaz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f5bac216-ca7e-4ca7-ae4d-662a6eb8b16a/16073735145.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/842c63b7-72e6-4942-8331-f4b1233649c6/football_manager_16_system_req.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/10bdebb0-aead-45b4-9640-0bc8d126c418/augustine_confessions_summary_book_2.pdfIn PDF document text
    • http://jewofeket.onlinewebshop.net/mst3k_outlaw_of_gor_song.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f8d8f8e3-b08f-43b2-a0d4-eb3d2f42af3c/30327526178.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d50d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD50D 2952 bytes
SHA-256: 3658acfb437ee7b67a1e9fd6aeb7f15b70df94427511d98d0601da9b3827ffdc
font_01_sfnt_off0000df94.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDF94 4956 bytes
SHA-256: 84675121a15cb307a82e21dbf25e6a6d4fc9a2bc710641af275be66f32feaf08
font_02_sfnt_off0000f05e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF05E 1800 bytes
SHA-256: a36eee06fef6ce219692c4ec918276ac99413e4fd1e3666e4031624f9289d620
font_03_sfnt_off0000f8eb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF8EB 10028 bytes
SHA-256: e8c40c8fa319b44a2308af412dd20b73cc8fb0f6e77aa21c0c62197bce7aa43d