Malicious PDF — malware analysis report

Static analysis result for SHA-256 e6bba6ed4a0b7318…

MALICIOUS

PDF

95.0 KB Created: 2021-06-01 09:40:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-27
MD5: 2ee8be7c3252344d2558df99ec941199 SHA-1: f4d5008035e8898b5e48ba4424602315770e6eec SHA-256: e6bba6ed4a0b7318622dc4e76ea8460ebeaef60bf70be7acdef5cacbe39267ff
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with one heuristic specifically identifying a 'link farm' designed for SEO manipulation. The primary malicious URL, 'https://pixomot.ru/pbw?utm_term=teacher+portfolio+template+pdf', is likely intended to redirect users to a phishing or malware distribution site. ClamAV and ML classifiers also flagged this PDF as malicious, indicating a phishing or trojan threat.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pixomot.ru/pbw?utm_term=teacher+portfolio+template+pdf PDF link annotation
    • https://rizomoxus.weebly.com/uploads/1/3/4/5/134589692/1808a362315.pdfIn PDF document text
    • https://wopufibirebosaw.weebly.com/uploads/1/3/4/4/134466277/2869370.pdfIn PDF document text
    • https://tasakexer.weebly.com/uploads/1/3/4/6/134669330/f13b1a7de.pdfIn PDF document text
    • https://bekazavaf.weebly.com/uploads/1/3/5/3/135327011/vojidimapokijep.pdfIn PDF document text
    • https://pezuzaje.weebly.com/uploads/1/3/4/5/134577214/5368f6c8f1b89ba.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/c0ec52cf-015b-4c9d-b48f-cbed5cc359aa/musical_notes_names_and_pictures.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c43bd56f-c7dc-4b5a-9fc9-28affe9e89fe/butebivojonodusodojepi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/40385cfe-b040-4cc3-a3b7-4079734f108f/how_often_do_marines_train.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fbb520ed-b915-4295-8a68-cabb0f311c3b/48800428733.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/089fd8be-4674-4515-ab1e-a56dcd5293fb/rainbow_e_series_parts.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/39dc102e-a9dc-4b33-abdd-29ca6b3afa36/how_to_replace_belt_on_older_maytag_dryer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/600458f8-f5da-4b38-ba48-1201ee729901/dr_phil_dog_personality_test.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/38bbbe73-1f29-4dd8-b69e-ef9408ec4037/fiche_de_lecture_sur_lecole_des_femmes.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3ff4f4cf-1814-4306-b2d2-390cd936a391/64225141508.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8959cc92-683f-40b2-9062-7505453c7565/how_to_thread_needle_on_brother_xm2701.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3eba09dd-1d38-4e9a-acf6-6fd075ddc595/lamamepuzolilinumekemot.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a070171c-da1c-41f3-9eef-67261b73fd79/42993277527.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/53f6a858-0e4b-48b4-9d87-34a7e640c599/how_to_write_a_case_study_analysis_social_work.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fd6b78fa-a8c3-4f39-b31f-22550d032783/gexugab.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b1818f4c-60a0-4389-a0e4-8e8176af7b49/h2o_mop_x5_steam_cleaner_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/edf614b1-238b-4908-bc0e-9150efd382e7/73394934378.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/91577deb-681a-4051-b329-1576c0c73733/85519872587.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1e15ae66-60a1-4f7e-8e74-5cf47b842a81/mibofotagijusulam.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cc1397a0-6add-4eac-bc99-ef2adf15b0c6/83153379642.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/22031880-6ebb-419e-a934-37df0f365a66/how_to_connect_dvr_receiver_directv.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001355b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1355B 5164 bytes
SHA-256: b72266e658a1e3aa73800d8f8d579e8a0a1840da17c8c2bf24e087f6b18fc97b
font_01_sfnt_off000146c2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x146C2 11648 bytes
SHA-256: c4976654c2ba828b46296aaa5bbd01c3b9b3c99e7db62c3d18314979a6c6b6fe