Malicious PDF — malware analysis report

Static analysis result for SHA-256 db3ef5ea9852e37b…

MALICIOUS

PDF

79.1 KB Created: 2021-03-21 00:52:45 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 69f067af29d23dd8448befd11810fb1f SHA-1: b2e2dcc69e592eccedad623457d6d0336b1896a6 SHA-256: db3ef5ea9852e37bf52adc8b863bd9b4ba15e4521873b32e427a125837391bf2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=why+did+the+us+intervene+in+latin+america+during+the+cold+war PDF link annotation
    • https://cdn.sqhk.co/pejozujemu/fcx4wgi/25574524784.pdfIn PDF document text
    • https://wipedevibenisi.weebly.com/uploads/1/3/5/3/135315865/jokepokisezagotale.pdfIn PDF document text
    • https://cdn.sqhk.co/jivonaxadu/agdfhgc/3d_bowling_boss_online_game.pdfIn PDF document text
    • https://bopisigo.weebly.com/uploads/1/3/1/4/131453919/6809197.pdfIn PDF document text
    • https://cdn.sqhk.co/ditetona/jeeRMjf/73951307347.pdfIn PDF document text
    • https://jukegiger.weebly.com/uploads/1/3/4/6/134668336/gujugexatosezi.pdfIn PDF document text
    • https://cdn.sqhk.co/bapisolel/h4Siyji/space_engineers_ion_vs_hydrogen.pdfIn PDF document text
    • https://cdn.sqhk.co/rugofufol/DmijeeF/wobojej.pdfIn PDF document text
    • https://sajofagexureleb.weebly.com/uploads/1/3/4/6/134652103/nezowomego-gozejinuzuxef.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/f76076e4-bf7a-4495-8724-3dee090f0154/what_to_put_in_sensory_table.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/25d286d9-f902-47fd-8a5b-6b8ae9315a5e/windows_server_2012_r2_standard_update_history.pdfIn PDF document text
    • https://s3.amazonaws.com/dafumuxitupav/zenna_home_shower_caddy_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/74e917b7-462a-4c6c-85df-ba4d7595ebd5/xotowefaka.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/72b28bb5-b705-4165-ad41-ba051035d1d5/2008_nissan_sentra_service_engine_soon_light.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/355767ab-5455-41e6-9331-9a0c8ee951ce/45189831130.pdfIn PDF document text
    • https://s3.amazonaws.com/jazamerijekufol/waste_to_energy_power_plant.pdfIn PDF document text
    • https://s3.amazonaws.com/lekezaru/4422884969.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a7f8558-10d3-44fa-9fc4-9b4131ece2d0/xakisemukezuxidiligonoti.pdfIn PDF document text
    • https://s3.amazonaws.com/dagasopones/mathemagic_answer_book.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/03255dd2-f63f-405a-ada9-19e922b2d015/marshall_jtm1_50th_anniversary.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f9928e88-9ad8-4d97-8cda-d0199b3c45d0/how_to_start_forex_trading.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3008df5e-fc77-47ad-8d98-b926aaad5d61/how_to_use_a_wood_stove_to_heat_your_house.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/93333845-9908-4ce5-8982-c53bfc6290c3/the_highwayman_by_alfred_noyes_analysis.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3dc4a2b3-62af-4d30-9706-8d0a9d1aac77/26611810655.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/532e27a7-31fb-4f3a-84d7-67be5c5d468b/how_to_change_my_logitech_mouse_settings.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1ac373f0-9564-4dac-8bfe-f71e620d7d25/how_to_use_cloud_weather_station.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f577.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF577 5620 bytes
SHA-256: d74e479bd6b6e94781ef4ff705087445bc17093beda5e720d0e822f11a19cfea
font_01_sfnt_off00010889.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10889 11000 bytes
SHA-256: 8d178f143d0bcac74b68863486092e3d84c25845a706e27550dc798ff1cdfdff