Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5ccc8bb425fa4ba…

MALICIOUS

PDF

67.2 KB Created: 2020-11-10 01:46:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-04
MD5: b7f0f99da60eb56601f020522407963e SHA-1: d830cff5bad0b5ad8f238617436878a282481e71 SHA-256: f5ccc8bb425fa4ba0515618db52ba4e9848b752575e702a81955a70a038c7d08
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/strik?keyword=minecraft+enchanter+ftb PDF link annotation
    • https://kokexofagisukop.weebly.com/uploads/1/3/2/7/132710589/9898268.pdfIn PDF document text
    • https://kukevukoleguko.weebly.com/uploads/1/3/4/2/134265740/15c59.pdfIn PDF document text
    • https://rajaxamakato.weebly.com/uploads/1/3/2/3/132302926/gafajifinime-lavodefikav-dilutitibol-nogunajizanug.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/b14aab5e-e3c1-4928-aa83-f8be40f22742/nuevo_testamento_interlineal_griego_espaol.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8aaa6f8a-e6b1-49d3-8895-302fa01d1d7a/pcms_drama_club.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ba9c1074-f54f-451c-8313-3fac4fbdb896/95231601456.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3cd2b989-0df6-48c3-96ca-df5bc7dcecdb/neben_mir_ist_noch_platz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fa462341-6b44-4e2c-b408-e11bb0eaab84/sfusd_calendar_2020.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6a1a0742-312e-4548-99ca-86f9a230bdda/pudexegi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9297922f-0e3c-4f0b-8a75-501fab2f2b7f/zatiwoxe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c96f1905-bb2f-455e-a069-808e386bcad6/21904791124.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a5fd197e-2119-45d6-a53b-13660beba638/10929017296.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7acc90f5-2222-4f39-aebf-448dc730a886/48582846151.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/48894389-c543-4347-99cb-e339fb5825a9/liwibalijegajajajad.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cba9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCBA9 4904 bytes
SHA-256: 09baea805eef79ba86c14daf8b4310b21adce0d72569c1f4d1dc17060538d5d8
font_01_sfnt_off0000dc63.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC63 10472 bytes
SHA-256: b4b77f03f34f97aa511532748127aeb8c3ea4b0c989914229fb002e67f960916