Malicious PDF — malware analysis report

Static analysis result for SHA-256 d490128d02884b8e…

MALICIOUS

PDF

74.9 KB Created: 2021-03-29 00:17:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 553d1da5d024cdfaf01ca88fe9250f75 SHA-1: 9e7eb33f896984fdd0a79de09f39a0ff86698c02 SHA-256: d490128d02884b8ec37a632f87e4b2f3cfb1d4e3d9b1a556a69b07eb4aa4e8b6
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/123?utm_term=writing+equations+proportional+relationships+worksheets PDF link annotation
    • http://adv-workshop.site/final_fantasy_6_rom_nds5vu15.pdfIn PDF document text
    • http://new-volosi.ru/present_simple_vs_present_continuous_exercise_online4ortq.pdfIn PDF document text
    • https://lomofoxagut.weebly.com/uploads/1/3/4/5/134524577/wuxapi-wudeterik-bemanupi.pdfIn PDF document text
    • https://baboxubawuxi.weebly.com/uploads/1/3/4/6/134666135/3997531.pdfIn PDF document text
    • https://vulabomanuxuw.weebly.com/uploads/1/3/4/8/134857085/4387851.pdfIn PDF document text
    • https://wonidajubiput.weebly.com/uploads/1/3/4/0/134017859/notimebumizopabuwi.pdfIn PDF document text
    • https://godikifamubexi.weebly.com/uploads/1/3/4/6/134622632/2952391.pdfIn PDF document text
    • https://nimifitirujaga.weebly.com/uploads/1/3/4/6/134693460/vulorajawirija.pdfIn PDF document text
    • http://streamsweets.com/pobugasudb1dm7.pdfIn PDF document text
    • https://gunobodupisar.weebly.com/uploads/1/3/4/6/134677737/tomonuguwo-borisemiv-jamoguru-kupar.pdfIn PDF document text
    • https://luxufaxunixepu.weebly.com/uploads/1/3/4/5/134584211/dede741888c.pdfIn PDF document text
    • https://kozuliwibiji.weebly.com/uploads/1/3/4/7/134705154/7608755.pdfIn PDF document text
    • http://instapodarok.site/nubufakorowrw91y.pdfIn PDF document text
    • https://zixojubagever.weebly.com/uploads/1/3/4/6/134613499/vofawabot.pdfIn PDF document text
    • https://lewofadexireg.weebly.com/uploads/1/3/4/8/134868993/jewigizitiw_roxumozi_miworamamajav.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://b86313a8-447b-404d-ae6d-bc69740d899e.filesusr.com/ugd/e54fc7_56bfee1ca9a4474c994832ba7dd3a616.pdf?index=trueIn PDF document text
    • https://1416a32c-f91c-4ec3-9c10-bfdf610c7df7.filesusr.com/ugd/76de1a_b1c1204a16244b9f99fbef29334d2512.pdf?index=trueIn PDF document text
    • https://5ee0d2ad-6486-47ce-ab7d-0e7b2bae4193.filesusr.com/ugd/bc0d1e_00234b7c55534bd5aa9ac92eb5535bac.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/24576a46-873f-445f-a7e5-e608b4ba6db4/remington_sportsman_11-87_reviews.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ea74a033-7268-4057-bf1d-584add346898/juwubum.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2b2a7cc7-bec8-4a72-b44e-f58b9b3b0bb3/how_to_replace_fisher_and_paykel_dryer_door.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e6b9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE6B9 5376 bytes
SHA-256: 6f8d104175846e8cc682ee29ba37f572cef685dc40ce8944e4af736c7b8c1988
font_01_sfnt_off0000f913.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF913 10796 bytes
SHA-256: 53f95bf23f892b7f4258fb2730f2b96f066ba20bf76f29818ffb227d5ca52420