Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3b6146e1cd69706…

MALICIOUS

PDF

84.8 KB Created: 2021-03-14 17:43:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: 900cc54f97a3b4e26627992586b18944 SHA-1: e0f2af79d7a6897523161df60fe1efe1070ec365 SHA-256: f3b6146e1cd69706ce8d68b83cb979e6e5290662e7853755bfcd3348a4f26aca
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/strik?utm_term=air+force+portal+2020 PDF link annotation
    • http://matawobedopikam.mywebcommunity.org/bubezubutar.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412415/normal_6042bc79c777a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470038/normal_5fe6bf169900d.pdfIn PDF document text
    • http://joweponula.mywebcommunity.org/casio_fx_115es_plus_display_decimal.pdfIn PDF document text
    • http://raxawevamavox.getenjoyment.net/12_week_calisthenics_program.pdfIn PDF document text
    • http://wasatosu.sportsontheweb.net/albert_beveridge_the_march_of_the_flag.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365661/normal_601c6a7690c61.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450046/normal_602286811c305.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://336ddc11-c37d-4cd6-9685-7accad2975f7.filesusr.com/ugd/479fa9_e562969116e14963951ce82bef8b9cae.pdf?index=trueIn PDF document text
    • https://49b7c339-fea6-4bb3-bf7b-ca47af5263df.filesusr.com/ugd/6ca12d_98009ec86b814074b5b6c6cd3f00a299.pdf?index=trueIn PDF document text
    • https://a72b158e-cead-41d6-a0b3-8518216316a4.filesusr.com/ugd/35c6e2_b2b584be325147f0994340597bc2053f.pdf?index=trueIn PDF document text
    • https://bc881323-2374-4635-a2b7-f126f9929bd8.filesusr.com/ugd/546a35_42b6acb51c1149bf862de16da480d931.pdf?index=trueIn PDF document text
    • https://0c3b2bb2-3ac9-4e0e-a0b2-530a831cdf0d.filesusr.com/ugd/23193f_e35e64d38f85400eb5cf2221c2735098.pdf?index=trueIn PDF document text
    • https://550dfcec-0280-4316-a0d5-68b74a7a20b9.filesusr.com/ugd/f59309_324a6b7f9f884f7cb4bffd412ce5f4a9.pdf?index=trueIn PDF document text
    • https://52a72965-a6d2-471e-b66a-59a59a4d663b.filesusr.com/ugd/e643da_901a7db8cf00497f90dccd76a5afd272.pdf?index=trueIn PDF document text
    • https://010f2e21-25ca-4560-806d-08cbbb7c7db1.filesusr.com/ugd/74a852_b046b685675740d9ba2a42896efcc4dd.pdf?index=trueIn PDF document text
    • https://7a3463bf-3117-47cc-940f-ad9d50d05675.filesusr.com/ugd/9f2514_3dd2d7b300344c91bff8401ad5454626.pdf?index=trueIn PDF document text
    • https://769966b8-4adc-437e-bba8-f198cf6e171b.filesusr.com/ugd/41a0b6_4cd1e9677f804e068783cce1ac17355c.pdf?index=trueIn PDF document text
    • https://28a90398-13b1-4b58-b54c-ed045a6bddf2.filesusr.com/ugd/7e9e1f_f0c54f2bc08942da8df455160acc2985.pdf?index=trueIn PDF document text
    • https://59e5a08b-0d8d-455f-a3a7-35a3b781ab3e.filesusr.com/ugd/784815_46432f33444d4ae7b5b006b731142c2f.pdf?index=trueIn PDF document text
    • https://bff5fdab-9fd0-4670-908b-a1308bb5a9cb.filesusr.com/ugd/227d0f_6a188e4893814dcb91b6200a975901c4.pdf?index=trueIn PDF document text
    • https://bd7a0a6f-bbfd-49cc-ba41-c3f2778102d9.filesusr.com/ugd/9ea91e_94914e55e87f4b468a6823d9a4297466.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001036a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1036A 4776 bytes
SHA-256: 33b4c89923338e5c04ba475a308fa2cac005d86169dc73f9ff9bbe767f745dfe
font_01_sfnt_off000113a7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x113A7 10696 bytes
SHA-256: 583ca4322f7d1613063b7526cc1762c93e9ead442e93c778d18e1a82d1d34bb1
font_02_sfnt_off0001380e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1380E 4324 bytes
SHA-256: 9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2