Malicious PDF — malware analysis report

Static analysis result for SHA-256 eece1296bcbab5df…

MALICIOUS

PDF

72.8 KB Created: 2021-03-13 14:27:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-25
MD5: a27a02a8b442ae801cc690ccf137cdcc SHA-1: b2bc096f9cbfc47b06137d70a5f3f12907ffbdf2 SHA-256: eece1296bcbab5df314de6952f64e19f3aaa35f6280b369ba0b673b44c8bff37
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many pointing to disposable hosting, indicating a link farm or phishing attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. The embedded URL 'https://seumenha.ru/strik?utm_term=solution+focused+therapy+quiz+questions' is likely the primary destination for the malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/strik?utm_term=solution+focused+therapy+quiz+questions PDF link annotation
    • https://tatujudipopef.weebly.com/uploads/1/3/4/6/134605081/9017325.pdfIn PDF document text
    • http://gimemuwet.mypressonline.com/how_to_train_your_dragon_plush_toys_light_fury.pdfIn PDF document text
    • https://poximixej.weebly.com/uploads/1/3/0/7/130776069/dc190c1db4.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://5b3500e9-40b4-440a-9ada-171ed8bcf4c9.filesusr.com/ugd/7820d0_1fe5b5fa2cfb49dd8ca2e81f0908e686.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/8cd0c239-5f79-4c50-887c-00de7f5b0180/tiwemarevi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f2bf328d-bdea-44a8-90e7-f16c0c2d7768/rarofumuxoz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/02f1aea3-d129-428a-9095-cf7d34520913/38086838100.pdfIn PDF document text
    • https://s3.amazonaws.com/rudelazifizuvo/stock_market_news_cnbc_live.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e1174755-607c-428e-a580-a26e1e0d0ef5/the_iron_curtain_over_america_john_beaty.pdfIn PDF document text
    • https://601bead5-a720-4f65-98db-62fe2a42cb91.filesusr.com/ugd/0e52b4_ef4d754929534f2ca3ab0fc44da686bb.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/dd182708-46de-4ac4-a119-f98ff7f5718a/what_type_of_oil_does_a_ryobi_generator_use.pdfIn PDF document text
    • https://s3.amazonaws.com/xulikamul/las_amistades_particulares.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/976565ff-9803-4101-834d-7400a44be6ac/ib_physics_ia_rubric.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f20fd144-fe7a-4a7b-a606-b223f86be109/strength_to_love_martin_luther_king_free_download.pdfIn PDF document text
    • http://rixuroruwe.myartsonline.com/how_to_do_the_kidnap_command_in_roblox.pdfIn PDF document text
    • https://c183b790-cb34-49aa-848e-1a9f2b14dda3.filesusr.com/ugd/d8966e_f6793a57dd6144f3b95680233f45fdb1.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/b917ef82-3b53-4eb7-aeb4-bde4783c26ee/gevobodelofixiven.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/062c9b22-916d-492f-a651-8e0f356f6c74/how_to_anoint_oil_poe.pdfIn PDF document text
    • http://zimopup.myartsonline.com/30399982126.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fb79b684-d8a5-427c-953c-8403e1661677/neduxawofo.pdfIn PDF document text
    • https://s3.amazonaws.com/gopuze/vidmate_apk_free_for_android_uptodown.pdfIn PDF document text
    • http://wojibikifi.myartsonline.com/holding_up_the_universe_quotes.pdfIn PDF document text
    • http://dolinoko.atwebpages.com/butipur.pdfIn PDF document text
    • https://3d7c42e8-cad9-4196-8f3c-0f210fd97588.filesusr.com/ugd/1b7c00_4a9f813568d74c6889fffd77dfdd2643.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e006.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE006 5624 bytes
SHA-256: 86a4c15880518ebc20a867a3f5a67eff28600819fc8846b040664bcd423601f8
font_01_sfnt_off0000f330.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF330 10060 bytes
SHA-256: 98597d3dcabab6d2e62b3b850e875f6055969a1c06ed995ceaf7e2a53f91b02d