Malicious PDF — malware analysis report

Static analysis result for SHA-256 ffbd85ecf15aa3cf…

MALICIOUS

PDF

78.2 KB Created: 2021-03-22 08:54:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: ecfa988cd0d23fe17037e80a10dbedcf SHA-1: d9a43529af41a229d02419287821d90acbc1235d SHA-256: ffbd85ecf15aa3cfd80f1c93f172a7a600b150fd0f2b05dcb28cb1b2f64fe3d9
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. It uses an urgency-based lure. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/wix?keyword=lax-max+new+generation+bluetooth+headphones PDF link annotation
    • http://dajexori.mypressonline.com/kapemefopezuwazesalus.pdfIn PDF document text
    • http://zugapuvu.mywebcommunity.org/zunapawabex.pdfIn PDF document text
    • https://rupubonu.weebly.com/uploads/1/3/0/7/130739332/zusujonalo.pdfIn PDF document text
    • https://nuribivavis.weebly.com/uploads/1/3/4/6/134625990/566415.pdfIn PDF document text
    • https://wisiwojapano.weebly.com/uploads/1/3/4/8/134896472/66516.pdfIn PDF document text
    • http://xijipeva.mypressonline.com/58162695097.pdfIn PDF document text
    • http://wugupomovupa.sportsontheweb.net/application_support_engineer_resume.pdfIn PDF document text
    • https://zetolame.weebly.com/uploads/1/3/0/7/130775520/pibororuse-rivogeze-vuvorexakirelep.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://51da6a7d-ee05-4a49-87ee-1b74af3aeb07.filesusr.com/ugd/b80405_6fff25fea089486185068a3bb0f7ab35.pdf?index=trueIn PDF document text
    • https://2f2ab42d-e0b4-4bd3-aa50-2430da1ff5fc.filesusr.com/ugd/eaf48f_d293a0f1dd2e497081e4c47ad259f90b.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/bab863fd-0ba9-49d4-a9eb-3ab266c8ce99/fe_civil_practice_exam_free_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/54780e1f-7ef9-4df8-8845-5a020bbc6ea4/fopoxafekuzagiw.pdfIn PDF document text
    • https://b1f0a730-f0e4-4bcf-918d-a915077b90d0.filesusr.com/ugd/a7c69d_6afb9d9241f84883be60090c29aa3ec0.pdf?index=trueIn PDF document text
    • https://5c839259-519f-4cee-a1a2-6639d654070b.filesusr.com/ugd/140efa_3b667deebd0640f6bada960edfc97075.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/f2c03f7e-b01a-472a-8246-33926d7eed0e/59721533195.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f56efdef-3f41-4155-acd8-b52b7a553211/77095038780.pdfIn PDF document text
    • http://wepogevadapafa.atwebpages.com/chapter_1_ccna.pdfIn PDF document text
    • https://67258aaf-84c5-4a88-bfd2-1aa7ddb6c27a.filesusr.com/ugd/850f07_2a12f32b5e9d443c86c995cdf4205850.pdf?index=trueIn PDF document text
    • https://8a5a474a-a671-4857-921d-d1df0ee72544.filesusr.com/ugd/523716_8d89c067777b4bc2ad2369be394a6650.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/da06cd51-7f45-48a2-9392-e08367f55a81/how_to_apply_two_stage_paint.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e4c8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE4C8 5528 bytes
SHA-256: 935cd83670f29f63a4e862763b5057b2b328684f5f699151378fb98da7509529
font_01_sfnt_off0000f77a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF77A 11128 bytes
SHA-256: 335237ee3dc66cc7a21cab8fdae112fc83597b61b0c52c40d88add4c8789982e
font_02_sfnt_off00011d5a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11D5A 4324 bytes
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f