Malicious PDF — malware analysis report

Static analysis result for SHA-256 c978f73bf2a6274f…

MALICIOUS

PDF

104.4 KB Created: 2021-03-14 12:26:38 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 53fa63d6295e2f3d3acb43fd07714e63 SHA-1: 371b2c55ed7602b6957b1ed9b1846c35769e6595 SHA-256: c978f73bf2a6274ff1b5247e447a1407e32e5f31b072ee64647183058f74b02c
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=best+forex+trading+books+for+beginners PDF link annotation
    • https://cdn.sqhk.co/tikisudolo/jCibqjb/94635908506.pdfIn PDF document text
    • http://biribekagupelu.66ghz.com/catholic_handbook_of_deliverance_prayers.pdfIn PDF document text
    • https://cdn.sqhk.co/rifokinimito/JfifYja/vijore.pdfIn PDF document text
    • https://cdn.sqhk.co/sawijewabob/cGjiii2/rogusotawefodi.pdfIn PDF document text
    • https://cdn.sqhk.co/tukawezezo/bhfjeja/zowawufovebuzadojeteri.pdfIn PDF document text
    • https://cdn.sqhk.co/jumosanex/fhejaWN/labim.pdfIn PDF document text
    • https://cdn.sqhk.co/kenujowemi/heK82gi/jixovuvomonase.pdfIn PDF document text
    • https://cdn.sqhk.co/wepunajexiju/cMiemid/itty_bitty_piggy_lyrics_az.pdfIn PDF document text
    • https://cdn.sqhk.co/letareximo/hiifYFO/the_outbreak_2019_film.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/papuja/facebook_cover_page_template_illustrator.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/91f8805f-5e2d-4125-9747-6c11cf312d9d/lg_wm2016cw_troubleshooting.pdfIn PDF document text
    • http://febiked.rf.gd/husky_8_gallon_air_compressor_air_filter.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2e9d5bb5-d511-4845-a2fa-add45e9dad55/ragudopotivixirebidoxubo.pdfIn PDF document text
    • https://s3.amazonaws.com/dobesogum/comparative_superlative_exercises_perfect_english.pdfIn PDF document text
    • https://s3.amazonaws.com/lerezazo/calibre_manual_stanley.pdfIn PDF document text
    • http://wewuvarek.epizy.com/28916180915.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4c562d72-c357-4197-8d21-099d5d76e578/la_catedral_del_mar_2.sezon_ne_zaman.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/167c0c60-f6e6-423b-a828-5a8d49decf48/what_happened_to_orpheus_and_eurydice.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bf8825e8-dcb4-4988-a933-c8aeebb0b68c/socratic_seminar_note_taking_sheet.pdfIn PDF document text
    • https://s3.amazonaws.com/xisefowu/backward_counting_worksheets.pdfIn PDF document text
    • http://sazubewotul.rf.gd/19984073117.pdfIn PDF document text
    • https://s3.amazonaws.com/guvovigo/51491038285.pdfIn PDF document text
    • http://sakikuzugodo.rf.gd/garmin_vivofit_jr_1_waterproof.pdfIn PDF document text
    • http://natetagawavitir.rf.gd/year_to_date_balance_sheet_example.pdfIn PDF document text
    • http://tadigolunus.rf.gd/83608168835.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00015962.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15962 5364 bytes
SHA-256: a846e817b281e1bbffc2c1c5bc43068e1d3b3829e3eeb76a37f32c92fbce55f6
font_01_sfnt_off00016bb9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16BB9 11752 bytes
SHA-256: 2dad400a629c6344d4967067a22940f6114212d66110982848aea1c10c489c17