Malicious PDF — malware analysis report

Static analysis result for SHA-256 db246f8629bea1f3…

MALICIOUS

PDF

139.8 KB Created: 2021-05-13 23:43:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 41450781d474c111181c68c81b44da7b SHA-1: 1882460ad3a5180673b52a6fce0833ef3af095da SHA-256: db246f8629bea1f31d7861ac055de4b6fbb26589906707002c7e90c4ea345b18
244 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm and routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9517

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=lord+of+the+rings+return+of+the+king+white+castle In PDF document text
    • https://degexaxi.weebly.com/uploads/1/3/1/4/131406510/4625364.pdfIn PDF document text
    • https://buzijivugaza.weebly.com/uploads/1/3/4/7/134709386/8470951.pdfIn PDF document text
    • https://binikefesomeb.weebly.com/uploads/1/3/5/3/135386190/2680698.pdfIn PDF document text
    • https://sibevuguz.weebly.com/uploads/1/3/4/8/134859718/a9dafdc656e6b59.pdfIn PDF document text
    • https://nidabiweni.weebly.com/uploads/1/3/4/8/134865500/1846699.pdfIn PDF document text
    • https://fabavowugofafif.weebly.com/uploads/1/3/4/5/134591931/zokukiz.pdfIn PDF document text
    • https://vigoruso.weebly.com/uploads/1/3/4/1/134131386/aa6853f5b5fe.pdfIn PDF document text
    • https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/bc8d625.pdfIn PDF document text
    • http://mevatupumave.22web.org/jaquar_sanitaryware_price_list.pdfIn PDF document text
    • http://tafugegajotu.mygamesonline.org/quotes_from_the_adventures_of_huckleberry_finn_about_jim_with_page_numbers.pdfIn PDF document text
    • https://kuxifegofemiza.weebly.com/uploads/1/3/4/8/134865321/aea4af873c8.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://kavejanunar.epizy.com/9529662646.pdfIn PDF document text
    • https://b1d4f555-1eac-4d61-aa83-27206cf3ee4b.filesusr.com/ugd/1706f5_b969cc745bbd491d8f6ef58b1fc9728d.pdf?index=trueIn PDF document text
    • https://9a60fab3-6fb0-4be7-9305-b2e3cc44d963.filesusr.com/ugd/811c4f_aee90bbe52b94790a7d646d6eaedb225.pdf?index=trueIn PDF document text
    • http://sibesexewelemu.rf.gd/android_studio_logcat_filter_disappeared.pdfIn PDF document text
    • https://71347f20-8353-4153-bebc-dd2a28b3a5cf.filesusr.com/ugd/a382ee_26ba0684459c4eb58f651f3607b9bac7.pdf?index=trueIn PDF document text
    • https://0dd0cd87-80d3-4eb5-b9c6-73c43c3a6fca.filesusr.com/ugd/f0b6b3_fca0050b7f0c4151a8e148634ece3e25.pdf?index=trueIn PDF document text
    • https://e0bfa911-60eb-4c53-bd8d-ceec25156dfb.filesusr.com/ugd/0a052f_84c4341d1734403a8b22423d1308de8c.pdf?index=trueIn PDF document text
    • https://95c758d6-fd33-43c6-b5d0-f1f55e07e946.filesusr.com/ugd/cb0188_90c7ed8207824f4e9133c32501c49f42.pdf?index=trueIn PDF document text
    • http://gubawakelu.onlinewebshop.net/aladdin_disney_story.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • http://sinhala.sourceforge.net/In PDF document text
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
    • http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.orgIn PDF document text

Extracted artifacts 15

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f8c5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF8C5 8444 bytes
SHA-256: 34645cb1c1bc6368e2d9098a981402bcfc9348c5aea338c7d016857bf3219fda
font_01_sfnt_off00010eaf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10EAF 5744 bytes
SHA-256: 905a00783a7d64519fbddba1fb8ca6a118abb07c96e3deb4eae6f6a1b5cdf842
font_02_sfnt_off000122c9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x122C9 5380 bytes
SHA-256: 141aeddb1d479910bfcc5cb001e7645d090f36b5d74a236f155ccda363f20dd6
font_03_sfnt_off0001352b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1352B 3608 bytes
SHA-256: 9c7a2cf8e2c0327abdb1727c22f967409fc401ca4e1e1ca1a97dbb05c188d269
font_04_sfnt_off000142a4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x142A4 4816 bytes
SHA-256: 8a3be85428e0fa87fa3db72745470ceb44961b2cb78a78e812fcd0eb1874e6bd
font_05_sfnt_off00015231.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15231 3180 bytes
SHA-256: 867e68df5fd4b49aeed2b5da8a5ea624ae841c03845c6f74ba1c07781381096c
font_06_sfnt_off00015e9b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15E9B 3164 bytes
SHA-256: 3357450d63624ca975ce527bbcc97714a35b745f099d232afdfa40a3c0428cb6
font_07_sfnt_off00016b67.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16B67 5740 bytes
SHA-256: 653965f5abe48e944b24df0fb82b70976e37744a7aea2dc0a2c2f80915f9af6a
font_08_sfnt_off00017e59.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17E59 3276 bytes
SHA-256: e16f98da688f0864a69ad05ce95b141e6d35f6d4cece9e78a44ea2b69431e3f0
font_09_sfnt_off00018b55.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18B55 4520 bytes
SHA-256: a53427798e763bd2561c1efee0d2a493638287672d204fecc1f6c5bcfaf6b8d4
font_10_sfnt_off00019995.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x19995 6920 bytes
SHA-256: 9ba331206e6eb8b8bdc760f94789263cb0fafacf953db5f9d978256c1822bb08
font_11_sfnt_off0001ac3d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1AC3D 14280 bytes
SHA-256: a0b002dc19ecbc0908dabf04684c431b91e67e01bc14fb32cc394a875d713d90
font_12_sfnt_off0001d8f8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D8F8 20840 bytes
SHA-256: db5c7974d91aea0dac68e1da6268fbf9f17466448cae981725660f46cf8708e0
font_13_sfnt_off0001fd35.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1FD35 3564 bytes
SHA-256: 61e885e5cf0e11295ff9597e1bdd4bae1b4d73c3d9a08f584ca908b83ebd7d1a
font_14_sfnt_off00020b13.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x20B13 5080 bytes
SHA-256: e9677554bf2e56cd33e6f387261ef06d13b8888f284dba48bf82e452d343062f