Malicious PDF — malware analysis report

Static analysis result for SHA-256 d2fe556a476c88a9…

MALICIOUS

PDF

74.2 KB Created: 2021-04-04 09:51:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: a41a0603f87ffbcfe96e52e76c9ed317 SHA-1: 50b3593dac075efb52b5783b6a19672eecc962eb SHA-256: d2fe556a476c88a9eee43b667a2dd4e55eda85f509dd3546e3f5d0cfad46a5b2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=fancy+pants+unblocked PDF link annotation
    • https://cdn.sqhk.co/metusoteliza/ichgvja/fuvewomonenem.pdfIn PDF document text
    • http://xuxetosufuzo.getenjoyment.net/2426480105.pdfIn PDF document text
    • https://cdn.sqhk.co/sanojuxako/aQhjzhd/47137878748.pdfIn PDF document text
    • https://cdn.sqhk.co/nemoludajedu/TggWgjM/funny_charades_words_for_adults.pdfIn PDF document text
    • https://cdn.sqhk.co/zidexamuwela/3hgijBd/road_champs_mxs.pdfIn PDF document text
    • https://cdn.sqhk.co/zefipuvuwifi/gfMhim0/5355262882.pdfIn PDF document text
    • https://cdn.sqhk.co/fovomesit/J5ghMz8/83787497016.pdfIn PDF document text
    • https://cdn.sqhk.co/lenufetimop/gARhiib/18915430466.pdfIn PDF document text
    • https://cdn.sqhk.co/surikuzezun/QxPgjuC/73757432798.pdfIn PDF document text
    • https://cdn.sqhk.co/vobipibomuk/b2ggphf/tic_tac_toe_classic_glow_uptodown.pdfIn PDF document text
    • https://cdn.sqhk.co/subilikiwi/idhhYjb/86895965884.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/bfdd8ab0-656c-44d7-80d8-8d8370370af7/how_to_program_my_dish_remote_to_my_soundbar.pdfIn PDF document text
    • http://vekamodadon.onlinewebshop.net/manojozewizorik.pdfIn PDF document text
    • https://438c9214-13ba-44a2-8469-a4c97ff43377.filesusr.com/ugd/5d46a0_fdcefd08e0b143d6af693191b8b5c586.pdf?index=trueIn PDF document text
    • https://e22e8d81-f41f-4d51-abb1-39b19d2d32bb.filesusr.com/ugd/96bf9d_3bba0d02702e40c7bb1c29ffe478830c.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/a7306124-7e83-414a-b2b1-4ae8c9848d78/41407928105.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/98d2ca2e-cf04-4b19-b445-68dc6261354d/1484446509.pdfIn PDF document text
    • http://jimomurapujivo.onlinewebshop.net/high_school_printable_book_report_template.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c2987c75-226f-498e-909b-4aa1fa9ce117/revolution_in_rojava_buch.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/089d609e-d2e0-4283-aacf-4b59e5cae7f7/mini_elm327_obd2_ii_bluetooth_review.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e6b4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE6B4 5232 bytes
SHA-256: 108ef7eb0625bffd133786d652c97d684c8453e2adfec7162858c402e1fb9b90
font_01_sfnt_off0000f898.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF898 10228 bytes
SHA-256: c86f4e1de5acf517bb4229347d7423e0f2204d79ddd9f1bb2ed58e7c679d0520