Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1c27ae93c169ee6…

MALICIOUS

PDF

82.8 KB Created: 2021-03-18 23:53:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: bdffa727e995ff451974b9667cc49014 SHA-1: 937eb43419c93a5f48b1e4c8892e62c35864a881 SHA-256: e1c27ae93c169ee63765893c94c0b8efd788071af75d2dc19727db8e73d34d6b
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/strik?utm_term=roald+dahl+films+online PDF link annotation
    • https://cdn.sqhk.co/xubuzivo/Yhcjczx/jufazurakoxupev.pdfIn PDF document text
    • https://cdn.sqhk.co/wanowofimaz/jgSidie/brilliant_time_meaning_in_urdu.pdfIn PDF document text
    • http://gufutaca6.xyz/giwukidewexadeojlbq.pdfIn PDF document text
    • https://cdn.sqhk.co/jotapepikota/hcHejbx/21753479261.pdfIn PDF document text
    • https://cdn.sqhk.co/vexelomuveg/cQ3cOii/rabafomuvilokitesakubo.pdfIn PDF document text
    • https://cdn.sqhk.co/tokarikadez/xjigdgc/rolling_sky_2_switch_review.pdfIn PDF document text
    • http://xepelewatelaziv.getenjoyment.net/business_english_for_beginners_cornelsen.pdfIn PDF document text
    • http://giveaway2020.info/ceropegia_stapeliiformis_propagation21uoj.pdfIn PDF document text
    • https://cdn.sqhk.co/lawafopugu/gfijhif/danny_king_s_catfish_bait_walmart.pdfIn PDF document text
    • http://mizarujil.mypressonline.com/antgeno_prosttico_especfico_psa.pdfIn PDF document text
    • https://cdn.sqhk.co/petebeki/gmRjbif/fazeviridotoz.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://8641c524-1fb5-4292-87ed-dd72f64d6c22.filesusr.com/ugd/9b7d8a_2269d4b9144c4dbab3c17d47812a770e.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/9e9ce58f-613d-4c76-8976-8e4d717441a7/brene_brown_ted_talk_vulnerability_summary.pdfIn PDF document text
    • https://80172413-d145-4b71-b7cf-4a007d76ad29.filesusr.com/ugd/cacfd7_6d7e63f42d8b4d86a42e552f67e594cf.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/ac029faf-d721-4dda-a565-2b74d63eddf5/5471377707.pdfIn PDF document text
    • https://cc6d8859-fc08-4100-a073-55b48c5addfc.filesusr.com/ugd/238140_b1c5b6d30ea74ef399fb6a091862bf5d.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/90df539b-c1d1-4910-8e7e-22aff7c08146/what_does_blessed_mean_in_matthew_5.pdfIn PDF document text
    • http://wipibefab.onlinewebshop.net/rapidex_english_speaking_course_telugu_book_free_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0ea60e9a-bd63-425a-a145-8e46d19be30e/safojezafemaketasibixuv.pdfIn PDF document text
    • http://natukifuza.atwebpages.com/pekaliwawowoxapoxu.pdfIn PDF document text
    • https://c63359c4-faa5-40af-ad11-254ddd3d100c.filesusr.com/ugd/838c33_e0ecbbfb72b1451d8c1a0a59752d44d2.pdf?index=trueIn PDF document text
    • https://0a37a3d5-a0bf-4e77-8ff5-6127fd08aefa.filesusr.com/ugd/6046c9_9f26aa706e0f48a581ea10cbdadd5100.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001074b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1074B 5056 bytes
SHA-256: 9a3f7586e662184e7f604bdabed94bcd13c95e73d7e6b383600b62f980da0601
font_01_sfnt_off0001185c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1185C 11268 bytes
SHA-256: f0b9ca5a08a9df0d48fe9eb979c786c9156cf2be4d74b1bdcf35a0725ca7843d