Malicious PDF — malware analysis report

Static analysis result for SHA-256 c9e45ad1f4c2bf65…

MALICIOUS

PDF

73.4 KB Created: 2020-11-10 17:41:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: 2b30fbd165b1ec22ccdebddfec510eab SHA-1: 536314130d3b1957f8242c7178fe6ce7e3df3840 SHA-256: c9e45ad1f4c2bf653def1e53b801110131bb600d80e63e9ead877b244bc6ada6
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/strik?keyword=turnip+greens+and+kale+recipes PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4369522/normal_5f88acc1c954b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4409393/normal_5fa34a103c4a4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369152/normal_5f901b1e3b573.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366642/normal_5f8cb46d5c65f.pdfIn PDF document text
    • https://dudezixibuwido.weebly.com/uploads/1/3/4/5/134529197/bowepuk-benekina.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/1fd26ffe-57b2-486a-aff3-26eaa741d2e9/rewisolanamowisawejiboni.pdfIn PDF document text
    • https://s3.amazonaws.com/fuwawibu/adjustments_by_international_agribusiness_firms_are_generally_made_in_the_area_of.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e9befbd5-399a-4bc7-b673-87d3f8301fb3/99696759388.pdfIn PDF document text
    • https://s3.amazonaws.com/zidosozawok/camp_high_harbour_lake_allatoona.pdfIn PDF document text
    • https://s3.amazonaws.com/gaxuremewuger/vejodelawejovupas.pdfIn PDF document text
    • https://s3.amazonaws.com/zurovajij/povogeru.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6e476fc9-5040-46c1-8d2a-6ac4df018c06/foroditirawuvipep.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2ada69e1-48af-41f1-9f5e-dc5fa90604e0/71955892599.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f1c846b7-e2db-4838-b30e-d41e9aaf73b4/43252053701.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/55b5452c-cdc1-4a51-af09-a768da0d9708/94557488646.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d4c3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD4C3 4948 bytes
SHA-256: 46230a8d8edadbd53465fc36e70a4833c368cc51796ffc2825bf8ffd69606e84
font_01_sfnt_off0000e593.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE593 10732 bytes
SHA-256: 458ff70df0129a80fec3af05fa390e5f56a0a868469d36a014461b89892ad9d7
font_02_sfnt_off00010a4b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A4B 4324 bytes
SHA-256: 1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e