Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe359e9726830a0b…

MALICIOUS

PDF

74.6 KB Created: 2021-03-31 02:12:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: 4395e57914f93fb92d59dfdf06263832 SHA-1: 4c45672d2297550f049d88979daca1a408ba6cff SHA-256: fe359e9726830a0b0008de998636aba423b0bddb9b44b63f7707e598ec6519d3
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=what+is+120+100+simplified PDF link annotation
    • https://lajexupizad.weebly.com/uploads/1/3/0/7/130775806/2104488.pdfIn PDF document text
    • http://gofidiva.iblogger.org/ruvawujetarid.pdfIn PDF document text
    • https://pigegiwoxare.weebly.com/uploads/1/3/5/3/135385020/698ce5fb23d.pdfIn PDF document text
    • https://ruzudewalaxuge.weebly.com/uploads/1/3/4/4/134497745/cbd52dd.pdfIn PDF document text
    • http://memiwuv.mygamesonline.org/8504667375.pdfIn PDF document text
    • https://lufisadoxusixa.weebly.com/uploads/1/3/4/5/134583632/miminasusukibef.pdfIn PDF document text
    • http://dewisazovuvoxi.mywebcommunity.org/kusesapuwatunonagedogela.pdfIn PDF document text
    • http://samemere.mygamesonline.org/ballast_water_system.pdfIn PDF document text
    • http://sezugoramilepep.22web.org/95718384948.pdfIn PDF document text
    • http://kafofal.mygamesonline.org/57296170983.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://mujawonevafo.rf.gd/dujifunew.pdfIn PDF document text
    • http://bozalusi.epizy.com/letter_format_change_authorised_signatory.pdfIn PDF document text
    • https://9d76d0c6-5807-43ac-a2ba-7b4112d1a20a.filesusr.com/ugd/5cd33b_d72cd9885aea43dd97ee6b46d509ff09.pdf?index=trueIn PDF document text
    • https://19aaccd0-9772-41b6-85c4-be118606641a.filesusr.com/ugd/a12125_537fde113ba14104933f8eaeff8ad89d.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/c496ac8c-4ab5-4082-b6a1-f5e8729bf3b8/86416574984.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a8010028-e548-4ddc-a926-7a8e2e47f224/7649966533.pdfIn PDF document text
    • http://suginuzebaluwom.rf.gd/jogesuwujutivupafagu.pdfIn PDF document text
    • http://kakidaja.rf.gd/98006251518.pdfIn PDF document text
    • http://pajomer.epizy.com/modern_haggadah.pdfIn PDF document text
    • https://fc06435f-e709-4c80-b59d-96fa470c1a13.filesusr.com/ugd/bdc04d_6b138a72c5b54ace89e933493778da9c.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/f40338d1-40a1-4e09-8a7d-3909d4b23ed5/whos_afraid_of_virginia_woolf_1966_full_movie.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d906.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD906 5096 bytes
SHA-256: 8ee21165f9cc954e8b078273c85f2e8f42f4244d1e4b120dff61a4a11926e9c4
font_01_sfnt_off0000ea6c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEA6C 10792 bytes
SHA-256: 77e78f1b206c09e26fb86bc1745f873f15b4430ee5303dcfbf4a99e092c7884a
font_02_sfnt_off00010f1d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10F1D 4324 bytes
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3