Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee4c358eb174564c…

MALICIOUS

PDF

88.1 KB Created: 2021-04-02 05:57:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7199254098db5e847641ebad7e159f44 SHA-1: 78f36f11f55ac366996f776a368acbda917d3af9 SHA-256: ee4c358eb174564c0a1d17210eb9b419c169a7ee1057e2980f0dd0175e726974
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The heuristics reveal it functions as a link farm, containing numerous external URLs designed to redirect users. The primary URL identified is https://soxebez.ru/wix?keyword=lifetime+fitness+south+austin+texas, suggesting a potential phishing or SEO manipulation tactic. No scripts were extracted, but the PDF structure itself is used to host these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=lifetime+fitness+south+austin+texas
    • http://lemafesopeposuz.mywebcommunity.org/sample_cover_letter_for_job_application_through_email.pdf
    • https://medotufise.weebly.com/uploads/1/3/4/5/134512565/9499764.pdf
    • http://nuveclovet.xyz/how_to_download_audacity_on_mac_catalinarfvbu.pdf
    • https://babinekisifuve.weebly.com/uploads/1/3/2/6/132696104/gusolidulava.pdf
    • http://gavokofubafixi.getenjoyment.net/demewavodabu.pdf
    • http://getsol.xyz/xagirefojifikitodapajedol5pist.pdf
    • http://werenntaq.online/dan_brown_books_about_robert_langdon67l47.pdf
    • http://gtmedis.com/tokyo_ghoul_re_manga_vol_3bd592.pdf
    • http://allostar.buzz/xajekebaxylmb9.pdf
    • http://duwinijuj.mypressonline.com/how_to_write_an_essay_linking_sentence.pdf
    • https://xolesozetenosox.weebly.com/uploads/1/3/1/0/131070434/kezofilafisoni.pdf
    • https://perikoweb.weebly.com/uploads/1/3/5/2/135297066/lufawetivi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/4f2c43b3-ed9c-4eee-9a28-83432c9928f1/what_should_my_toddler_do_at_18_months.pdf
    • https://a54de82d-0003-4787-801b-d7ee719c780a.filesusr.com/ugd/8d57bd_a5dca49d155b499ca75c4aeca03940af.pdf?index=true
    • https://368051e9-4199-40ea-b9a2-dc6e6f83cb3b.filesusr.com/ugd/6260fe_2f60278342114cb7b607c0b26e68663d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/2c7bc822-17af-4b64-93a7-ecd62fc77272/70374518362.pdf
    • https://0879403c-3be5-48e4-925f-21334a7d5cfe.filesusr.com/ugd/407fcc_42f11e51c49f4c6fbac60e86eec471a3.pdf?index=true
    • https://uploads.strikinglycdn.com/files/29d5bae3-ca99-4ce5-84c2-19f0a0507088/how_to_service_an_insinkerator.pdf
    • https://2b08c346-38d8-4763-b559-bb9d4fff2313.filesusr.com/ugd/40c9d6_0ddb9fa05921427babbbd9fd45eb9a34.pdf?index=true
    • https://uploads.strikinglycdn.com/files/cc35b40e-033c-4e8e-b562-e5bab98ac6f5/call_me_by_your_name_2_trailer_deutsch_online.pdf
    • https://uploads.strikinglycdn.com/files/1b7d1881-83b7-4b49-95b4-79e969ee315a/best_math_book_for_grade_4.pdf
    • https://5c3e38fa-bf2d-4cda-bfdc-19e9a39f2227.filesusr.com/ugd/b3ada4_da8a3e57eb79480888232a5e7d44ec1e.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001066d.bin
68e2318c9c82f009a8154b5b7f2d8bb75eef5414905c0966f7673b3331c120de
pdf-font-stream PDF embedded font (sfnt) at offset 0x1066D 4888 bytes
font_01_sfnt_off000116fb.bin
709f0285a1e3af290256c0510a2fd31033e5d0b22747efac006324efc4cb82a3
pdf-font-stream PDF embedded font (sfnt) at offset 0x116FB 11424 bytes
font_02_sfnt_off00013d4d.bin
a9f6f832ac6db2c07fedaded388bbbc825938349848724d68f73651b0518da36
pdf-font-stream PDF embedded font (sfnt) at offset 0x13D4D 16176 bytes