Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe64c8ab2ac6a774…

MALICIOUS

PDF

67.8 KB Created: 2021-03-18 03:48:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-10
MD5: cc9c0955fc4bc2b63d637032ae2ef601 SHA-1: fc2b36a27900b4aa98747ca9d67e23988d70bb3c SHA-256: fe64c8ab2ac6a774489afd7a8b86fe290441fff9c8dadcbb6f2daedb32943f19
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains numerous embedded URLs, with at least one pointing to a suspicious domain ('soxebez.ru') that is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, suggests a lure related to educational worksheets, a common tactic for social engineering.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=free+compound+word+worksheets+for+kindergarten PDF link annotation
    • http://lerob.info/87170343242k6d59.pdfIn PDF document text
    • http://ruzoboxilotazex.22web.org/what_inferential_statistics_do.pdfIn PDF document text
    • http://triple-doska3.club/52256772388h8991.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://d0275d90-c5b4-4c72-b581-d0e2b62fc6dd.filesusr.com/ugd/ee54da_6e844b0ecc144530b784297626cf79a1.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/1ac305e7-e92f-4635-b71d-ff86a5ef815c/how_to_clean_keurig_2.0_k400.pdfIn PDF document text
    • https://305aa2e3-e1d2-413d-aa2e-f1bb83d03ded.filesusr.com/ugd/92ee2b_5593f2e2441c49b49541907427926fa6.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/042d92db-ab33-4260-a4c7-0a7ab7c118f3/what_scooters_have_gy6_engines.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/42daa8ee-7554-4a13-8e61-aadd62b48fbf/soboda.pdfIn PDF document text
    • https://s3.amazonaws.com/dosipive/how_to_open_the_back_of_a_timex_indiglo_watch.pdfIn PDF document text
    • https://cc968bdf-8a18-4a65-a72d-893c706ef441.filesusr.com/ugd/bae363_0cce5bcee3704fa2b8fbfbb729382396.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/jufowokedunod/datak.pdfIn PDF document text
    • http://rowodebifofida.rf.gd/altium_designer_viewer_summer_09.pdfIn PDF document text
    • https://13fad4bf-7224-44b3-802b-16842e97d241.filesusr.com/ugd/b14664_50d3b4976b1e41079f5d4029204339d2.pdf?index=trueIn PDF document text
    • http://tejusadesivuti.epizy.com/mark_carpio_music.pdfIn PDF document text
    • http://vaxikiluso.rf.gd/wusoxukimoxuxerubaromutis.pdfIn PDF document text
    • http://tesoduv.rf.gd/blood_bowl_2_starting_dwarf_team.pdfIn PDF document text
    • http://toxerisana.epizy.com/midabu.pdfIn PDF document text
    • https://s3.amazonaws.com/zedilegol/tejuxefebumepazurivoxo.pdfIn PDF document text
    • http://piredesoki.epizy.com/fevejibutobujonab.pdfIn PDF document text
    • https://s3.amazonaws.com/gebukil/email_marketing_platforms_for_nonprofits.pdfIn PDF document text
    • http://zefuxaninegug.epizy.com/apple_developer_center_xcode.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e74be8f4-89cb-4d21-92d3-50a63e3fd3d7/3121908971.pdfIn PDF document text
    • http://gimusatis.rf.gd/divul.pdfIn PDF document text
    • https://9170d309-caca-4186-8987-bf6b40ce219c.filesusr.com/ugd/baef12_d45505b94fd5409a8cebd567b1b60d24.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cce8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCCE8 5648 bytes
SHA-256: ec5a58772e4191cefbea30a17cecce70b85be9a31f9675d6673d231489049deb
font_01_sfnt_off0000e00f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE00F 9712 bytes
SHA-256: c8c407a3d1f9922b4d56acd5157de4e894573b4d3198b4d4dcca4bfbd605d2bf