Malicious PDF — malware analysis report

Static analysis result for SHA-256 f0d9ec2f0eeba9ff…

MALICIOUS

PDF

78.9 KB Created: 2021-06-09 16:56:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-13
MD5: 92eef212729bbf7fd2ce69ddb842b7c5 SHA-1: 7ec48fc672c2faa5f93b9ab5908bdd4a2cbd7c99 SHA-256: f0d9ec2f0eeba9ffadc8714bfde4e2df40bf423522250bb3193dab0594c9c252
226 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document is classified as malicious by ML and ClamAV, indicating a high likelihood of malicious intent. It functions as a link farm, directing users to various external PDFs, one of which is hosted on disposable infrastructure. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' suggests the document's purpose is to trick users into downloading a password-protected archive, a common tactic to bypass security scans. The presence of embedded URLs further supports the phishing and malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://medvor.ru/pbw?utm_term=download+gta+san+andreas+obb+200mb PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4486061/normal_5fdfbe1f98ab5.pdfIn PDF document text
    • https://jipunone.weebly.com/uploads/1/3/5/3/135349916/8131402.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4421637/normal_5ff07fb08d4c3.pdfIn PDF document text
    • https://togawikanow.weebly.com/uploads/1/3/5/3/135320583/gafulume.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4503767/normal_600ff20a729ec.pdfIn PDF document text
    • https://wafodefa.weebly.com/uploads/1/3/4/4/134480145/migizawewikuwutogijo.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4385869/normal_6062f10ee8d58.pdfIn PDF document text
    • https://static.s123-cdn-static-d.com/uploads/4458431/normal_60aff2a1d9745.pdfIn PDF document text
    • https://bezujaseda.weebly.com/uploads/1/3/1/4/131437953/c48058bea83b1f0.pdfIn PDF document text
    • https://sifoginugiji.weebly.com/uploads/1/3/4/5/134588619/a5fbda.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/ac81eb83-538c-4f69-8e65-913dbc1da253/nexus_9_android_10_update.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7a2b4652-eadc-4036-abae-23e63de4c463/sufutaderaguzoluvizigutir.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ee08da6f-5b09-4e78-95f6-f67cc0b16970/sojegojawokugurivalut.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ad48cf52-fd5c-42b6-a5a7-cb48438c9566/vevurusanilula.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/25eb29c2-4626-4a2f-a077-b9f6a6e43bcf/gym_workout_routine_muscle_gain.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e839fd55-10a7-4468-ab46-656841ac90d1/how_to_get_a_fork_truck_license.pdfIn PDF document text
    • http://pokuwatosat.pbworks.com/w/file/fetch/144555702/88498762130.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/48ea8a55-e697-4612-adf7-b82cbfefbdcb/27859694648.pdfIn PDF document text
    • http://liwuvedesisu.pbworks.com/w/file/fetch/144578643/23055763020.pdfIn PDF document text
    • http://feselikebapu.pbworks.com/w/file/fetch/144891699/ssf2_0.9_b_unblocked.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3d21946d-c27a-4604-9d26-81ad230962fb/36136785743.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4a3d4c9b-4c31-4be7-b2c1-4bce2f17567a/mixinopejerojumeweremole.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/99b28bc1-033d-4521-8181-e55597f84891/sulawupenatirujupumisojof.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/33991294-d9e8-44d3-8f8b-061c76bcb1e7/what_are_the_key_components_of_realism.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dc19.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC19 5648 bytes
SHA-256: 80dafef6d538c6abb7183a0abd2817ba33ca03f096eb46bb5ca5433255cc14c7
font_01_sfnt_off0000ef56.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF56 10440 bytes
SHA-256: 75670bdd3ae24611ab9ff777835149f5d702f0024bc678699c32300b4dc4f93e
font_02_sfnt_off00011372.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11372 17112 bytes
SHA-256: 2699f2ce65472362c7cce2649b9a1ca315f2f35cd4c84f2de76f8c9cc61a5f56