Malicious PDF — malware analysis report

Static analysis result for SHA-256 d4f62cdc5bc98330…

MALICIOUS

PDF

80.1 KB Created: 2021-06-01 19:54:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-01
MD5: 16856c7d9b623edc99a8b83627544e8d SHA-1: 84ff508e4a0ad035f13d65d1ee63fff63e43c625 SHA-256: d4f62cdc5bc9833076186270821fef27594e2703b3c4776516d8d79c751ded11
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8730

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://krisoc.ru/pbw?utm_term=zanki+zero+stage+4+guide PDF link annotation
    • https://jutineriru.weebly.com/uploads/1/3/4/8/134866815/1496473.pdfIn PDF document text
    • https://boluzevorekov.weebly.com/uploads/1/3/1/3/131384542/xigudapigo.pdfIn PDF document text
    • https://vufobuvi.weebly.com/uploads/1/3/1/1/131163959/7091757.pdfIn PDF document text
    • https://soregekewo.weebly.com/uploads/1/3/4/2/134266411/bfb1e076b35648f.pdfIn PDF document text
    • https://wowifowukanu.weebly.com/uploads/1/3/4/6/134634936/gokirurusigilusa.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/92bf6956-8357-4d80-9869-cc5fa0cad3ae/43998425031.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/64b01638-0b49-4f4e-81f6-593de39b0a0a/bogafowebudogujerona.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa29ae43-56c5-424a-880b-ab96a789f1dc/how_do_you_convert_a_to_a_fillable_form_online.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ee5f274b-5175-4cc2-b529-a9a3bd32ce86/38196289264.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/da286320-7903-4929-a21e-38a911ea2ab6/how_long_did_greek_performances_typically_last.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5fb6291c-97d4-4d8c-9919-ec8ddb273f92/janome_hello_kitty_sewing_machine.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6564f42d-7d40-408a-9c41-4350688accb2/esl_list_of_most_common_phrasal_verbs.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f5d7dddd-179e-4aca-90a9-f02db3f313e1/dofipawosawabitexiwewiza.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6b825425-cafe-4f73-82e4-2527e7bba818/kibig.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e0431ad3-854b-4943-9443-5f0ef290368e/properties_of_matter_lesson_plan_high_school.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8169152f-4112-412a-866d-3f81952ea4dd/tibalukifugebolupawinarev.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/556f70cf-1b47-4fdd-afd3-5e0a9f78ac89/mevufitode.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a7c2010f-5c0f-42bf-8351-7c2d25cbe668/sifuwugezawepuwabowefevej.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cd8bad02-ace1-4eb9-9b8c-ca03ab1051a5/bupamomusukiget.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9b1a6d27-dc28-485a-a11b-6221025f2b71/is_steamunlocked_safe_2020.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d774fc0e-5713-4947-aa8d-2a3f97106c4a/toro_gang_reel_mower_parts.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/38f63d3a-1348-41c5-94c8-2e1a6946aa0d/44151190254.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b42f8697-823d-460b-a37a-9d9cf74afc66/what_does_restrictions_b_mean_on_a_texas_drivers_license.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e2de1e1a-3440-4ec5-8c28-47b39b1ba2f8/prisoner_b_3087_quotes_and_pages.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d657faee-1ca2-43db-bb2b-c3c5be29056c/how_to_put_batteries_in_black_diamond_headlamp.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d7a05db2-6fb3-4a73-86ca-4bea1f912eb2/50616587826.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b6b28398-08e5-4fba-ab0e-c8064ae9a9e5/70122097940.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a5546437-acb9-4e49-999c-5285ccfa473f/history_of_the_single_wing_offense.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dee5ab07-61d0-4cad-a0a5-698519e91951/31971589336.pdfIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010729.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10729 5120 bytes
SHA-256: 55d5b14a9bcceb8ddf9a73dc5c67e4022e833b13f59d2ad5df731cb63810f0a6
font_01_sfnt_off000118b7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x118B7 13624 bytes
SHA-256: 69f2f4a6eb97905215108c98ded97b7d843fb179beb42d0ab017b3648652bd2d