Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd22779e8dd86868…

MALICIOUS

PDF

80.0 KB Created: 2021-03-11 15:12:39 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 0167f8300d345eae2d2735766667c920 SHA-1: 18f65e5ed7bbd9f4de82237c15bb7b00ab27109b SHA-256: fd22779e8dd8686841e766c46c8c9a12d3959903adee27b4d2e59a9eca565767
134 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm and presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/aws?utm_term=canon+mp250+driver+windows+10+64+bit PDF link annotation
    • https://cdn.sqhk.co/tejosepu/fCxDegi/jusufiteteruna.pdfIn PDF document text
    • https://cdn.sqhk.co/tefozakozup/fLj9PoG/driving_experience_las_vegas.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4470967/normal_5fed00c1c4557.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4467273/normal_5ffd638746d53.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4414153/normal_603c69f791a29.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369776/normal_6019577b6d91f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4491927/normal_600bd42669519.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4402501/normal_60089d01d9ed0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4454286/normal_6005fa07c1c84.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370542/normal_60329b8a4ea23.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://0c2a7d7b-be9d-4ef2-a94c-09ca905cc17d.filesusr.com/ugd/7d21c0_19f6ea666b0344fe83ce240753150180.pdf?index=trueIn PDF document text
    • https://1c684d3d-b1aa-4d58-8f8e-408f9cf37fac.filesusr.com/ugd/64d889_b4e86c508f22424b906292f9150320a7.pdf?index=trueIn PDF document text
    • http://vobikeretuwof.atwebpages.com/befefolawufowiru.pdfIn PDF document text
    • https://37e0f79d-b0c1-4727-b76d-5b759c81288f.filesusr.com/ugd/9c66ff_6f044e0c40b94429b19121f389bf46d9.pdf?index=trueIn PDF document text
    • https://5b5cf7c4-d983-4e27-bd54-44d52fc9074e.filesusr.com/ugd/2f9450_689745b889bd4f04ac886bc5bdb44aea.pdf?index=trueIn PDF document text
    • https://a39ac558-8fe8-437d-9e10-dc9402d6cb9c.filesusr.com/ugd/1ebe14_8a7fb48533054a8ea9d6ba67c74898d0.pdf?index=trueIn PDF document text
    • http://domuromu.atwebpages.com/molecular_biology_techniques_resume.pdfIn PDF document text
    • https://e9593579-f51f-4dc6-af55-2543ab512b45.filesusr.com/ugd/37952c_61cf93e828c8451eb1fac480ea8bbd2a.pdf?index=trueIn PDF document text
    • https://80c93ba6-74df-4afb-9852-3a83eaba20e3.filesusr.com/ugd/4cf28d_a13eb57cdec942a49ef01491ffa8d39d.pdf?index=trueIn PDF document text
    • http://bifiwapaz.onlinewebshop.net/gevaw.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off000118a5.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x118A5 17380 bytes
SHA-256: 8167200ea4c27607d5adff8d1fea3b53698f604dabaeb2fc19387baa0aa98196
font_00_sfnt_off0000e003.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE003 5964 bytes
SHA-256: 113ab2a13e1528df792024847575072af43284af6cb04950e072ce7c73adfb97
font_01_sfnt_off0000f44c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF44C 10896 bytes
SHA-256: a6075ce89957667fc8fc818059f7003a57fc89258ac453f84ecdd782aa1b7df3