Malicious PDF — malware analysis report

Static analysis result for SHA-256 f47779f35550fe5c…

MALICIOUS

PDF

98.4 KB Created: 2021-04-18 09:59:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 8d1fba310576eb7db7ef40413433242b SHA-1: db8d191642d31a0db31dddc70b25c1238edee3bc SHA-256: f47779f35550fe5c3f6671db3143dc18ec7ecdfa26a053fd73fb770696ec7230
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9964

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/strik?utm_term=miniature+dapple+dachshund+puppies+for+sale+in+ohio PDF link annotation
    • https://cdn.sqhk.co/wibetaxor/jiigdhb/formula_1_racing_2016_game_for_pc.pdfIn PDF document text
    • http://twitter-center.com/streetrace_fury_mod_apk8ezfz.pdfIn PDF document text
    • https://cdn.sqhk.co/naruxibe/iaaLg6s/uppercrust_motherwell_opening_times.pdfIn PDF document text
    • https://cdn.sqhk.co/gusisezepemu/Hhjafid/the_dream_vr_inc.pdfIn PDF document text
    • https://cdn.sqhk.co/nipigagavadu/65IDuhi/nabotuwexopodufegavo.pdfIn PDF document text
    • https://cdn.sqhk.co/jalizovi/ju5ihgg/castle_clash_guild_royale_mod.pdfIn PDF document text
    • https://cdn.sqhk.co/joxesinejag/idicGYb/4452593131.pdfIn PDF document text
    • https://rumikupim.weebly.com/uploads/1/3/5/3/135310872/xegixi-wofad.pdfIn PDF document text
    • https://gegoviboz.weebly.com/uploads/1/3/4/8/134876631/tasetegilaxesiz.pdfIn PDF document text
    • http://vilopeg.xyz/are_there_still_american_bases_in_germanyezgdh.pdfIn PDF document text
    • https://cdn.sqhk.co/fiduzosi/ni1hbhh/95114953730.pdfIn PDF document text
    • https://cdn.sqhk.co/zoxunoromi/hjQmjeu/today_s_news_updates_in_english.pdfIn PDF document text
    • http://healthytrands.com/nukimaxerazdden5.pdfIn PDF document text
    • https://cdn.sqhk.co/pazakazagoz/SghdytM/texerimokopinilazufodoras.pdfIn PDF document text
    • https://ronewomiz.weebly.com/uploads/1/3/0/8/130874064/a75d68484f98.pdfIn PDF document text
    • http://kersita.space/washington_post_horoscopepgy0t.pdfIn PDF document text
    • https://cdn.sqhk.co/zapajugadira/iifWDhc/bubakefemavasiraw.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/f2e4a70f-9cca-4623-9224-6d816c911e80/27117882510.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/444f5065-db83-4a7e-8943-cdd64215b140/what_was_the_significance_of_the_temple_in_jerusalem.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1ee43639-c232-40e4-aa8f-a1acde2e1a20/what_is_the_difference_between_clear_and_concise.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2971e63e-8ee2-41fc-a292-42a7b605d7f3/world_war_z_pc_game_download_highly_compressed_google_drive.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/36d0cceb-f883-43bb-bf13-100f9265a15e/34323232922.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/68516d2e-f9e1-4d81-9842-3e1bd7f04ca0/digital_fortress_code_after_epilogue.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9be655f0-6e9b-412a-91db-6f98b9b85dd2/kovebu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e488b16d-0f19-487f-b267-67b84b948ecd/how_covid_19_affected_employment_in_india.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8c4fec15-e99a-4032-ae56-79b9dcb17615/panezimusaf.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c0a556b8-2743-4e1a-adce-fbe31c3f9dd1/62574554158.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001403b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1403B 5248 bytes
SHA-256: a4d388457e56115191546fc83174e831e90fd4c8aedcbea022736218193a35df
font_01_sfnt_off00015219.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15219 12316 bytes
SHA-256: 9159912c8933abc216ccb22fd95f6c4854e1347a485281d5d5f603ed144e7c92