Malicious PDF — malware analysis report

Static analysis result for SHA-256 ead6c3c73d425e90…

MALICIOUS

PDF

82.8 KB Created: 2021-03-08 21:15:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 7dbafba6e3b501afd0a368cb3760d02f SHA-1: 291daabb8c1f37c9a15dacbd6b7fee65d3dd8771 SHA-256: ead6c3c73d425e90f1aea69e8f2140a90db2237663ad29dd11a9fc1bc65e75fb
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9954

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=minecraft+vampire+mod+1.15.2 PDF link annotation
    • http://xatovapotogu.mywebcommunity.org/evinrude_6hp_outboard_motor_for_sale.pdfIn PDF document text
    • https://lizelizana.weebly.com/uploads/1/3/1/4/131409616/sikepaxode.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4469106/normal_60328021d4d18.pdfIn PDF document text
    • http://tonedomopoja.scienceontheweb.net/kunowiwegax.pdfIn PDF document text
    • http://xedeporib.medianewsonline.com/the_wifes_lament_poem_annotation.pdfIn PDF document text
    • http://jomikifu.medianewsonline.com/oracle_12c_sql_fundamentals_download.pdfIn PDF document text
    • https://jumuwaxenu.weebly.com/uploads/1/3/1/4/131406560/zujizadeladazimaxewe.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369494/normal_602291dfba43e.pdfIn PDF document text
    • https://betetudiju.weebly.com/uploads/1/3/5/3/135348010/gitosonufejega.pdfIn PDF document text
    • http://zereteleriw.getenjoyment.net/75376883887.pdfIn PDF document text
    • http://nuloriwilorij.scienceontheweb.net/ximidamamewixijulunur.pdfIn PDF document text
    • http://lifelalulenomip.mygamesonline.org/maytag_bravos_washing_machine_reviews.pdfIn PDF document text
    • http://jukojadijomefar.medianewsonline.com/types_of_crime_in_sociology.pdfIn PDF document text
    • http://jologedeb.getenjoyment.net/zamowowejefosupu.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370543/normal_60226ae46929e.pdfIn PDF document text
    • https://kafaxidaduxeb.weebly.com/uploads/1/3/1/4/131438036/5814742.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jupoti/upsc_prelims_2016_answer_key_paper_2.pdfIn PDF document text
    • https://0e8f88b9-656e-4b05-9cd8-8bd477f85547.filesusr.com/ugd/95b9ea_33d14da82192450d8dd1dd3c645f2fe5.pdf?index=trueIn PDF document text
    • https://3ff4c494-4984-418a-b709-7a5c611cca0a.filesusr.com/ugd/adbee0_5ed6d802203541f0a25dc9580d09df27.pdf?index=trueIn PDF document text
    • https://67a4337f-2b79-4d04-9c1d-2578c80f4945.filesusr.com/ugd/964009_446f22808e34463d8f65603207e1472a.pdf?index=trueIn PDF document text
    • https://8319d365-0190-44ee-b2f3-e76f6fd230eb.filesusr.com/ugd/112488_938e2952653f449dba8acaaf2091e164.pdf?index=trueIn PDF document text
    • https://011f98f8-b45f-4578-a2fd-466b530f7845.filesusr.com/ugd/74e905_88b6992307d74ea6bab6b6be6459839e.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/gagagakigibapo/how_to_adjust_eco_drive_citizen_watch.pdfIn PDF document text
    • http://vawirir.atwebpages.com/why_did_defending_jacob_change_ending.pdfIn PDF document text
    • https://s3.amazonaws.com/vavebufevodutob/wisodunirejijado.pdfIn PDF document text
    • https://s3.amazonaws.com/rogugagatuf/confidentiality_agreement_for_staff_template.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000efd6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEFD6 5496 bytes
SHA-256: 230890a09ab3be0c58b510b61797fe28c2d963317954d6d4336340919fafc608
font_01_sfnt_off0001029b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1029B 10684 bytes
SHA-256: 77dd495b31fcb75ff3fd28ae781aff5a0dd7416b93ec31010fce7b4d34a2af88
font_02_sfnt_off00012726.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12726 16064 bytes
SHA-256: 6f41d85279102efce3c4bd26fddb767baf9b68a4f55e239fba9bedc2a2d3b953