Malicious PDF — malware analysis report

Static analysis result for SHA-256 27aa4f89bc48d39a…

MALICIOUS

PDF

77.4 KB Created: 2021-03-17 18:06:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 31ce9f239872dfa308329173550bb3ee SHA-1: 908e530dd8ceb27a2cde17293e5c876679061904 SHA-256: 27aa4f89bc48d39af1b09dc1451d45e5c6b7abe7061826539f84d7fa3f216c78
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The primary malicious URL, https://botokaw.ru/123?utm_term=axes.+io+mod+apk+android+1.+com, is likely used to redirect users to malicious content or phishing sites. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=axes.+io+mod+apk+android+1.+com
    • https://gizepigonezes.weebly.com/uploads/1/3/4/9/134901759/7f2bcde.pdf
    • https://cdn-cms.f-static.net/uploads/4465908/normal_6028fe8b6dff3.pdf
    • https://bowetupivivuz.weebly.com/uploads/1/3/1/4/131437724/94665628604f.pdf
    • https://rukegimamu.weebly.com/uploads/1/3/3/9/133986924/novupasiwimelefime.pdf
    • https://static.s123-cdn-static.com/uploads/4473031/normal_5ffdfe9449c19.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/e4fce096-19bd-4096-bfb8-fee065fd746f/47965462254.pdf
    • https://uploads.strikinglycdn.com/files/9be5fdbe-3037-4ced-af8a-bd5399eddaa3/how_to_clean_bissell_powerforce_helix_filter.pdf
    • https://bff5fdab-9fd0-4670-908b-a1308bb5a9cb.filesusr.com/ugd/227d0f_f0fd8f92a08240b19a1477fc3f02037d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/96ea81be-7580-4d11-a442-bc25481fa599/lamenoxovudabilunozumebek.pdf
    • https://c84d532c-3b33-47d6-96aa-4134a1164eb1.filesusr.com/ugd/6d45f6_8b02c99334a74787998ab16fcf342d43.pdf?index=true
    • https://uploads.strikinglycdn.com/files/fd9221e1-0c6e-4887-9974-e88c4143462f/what_is_a_very_good_sat_score_2019.pdf
    • https://s3.amazonaws.com/gagagakigibapo/xiriragetetazolavakodagu.pdf
    • https://e5447efa-8854-4d04-834e-f0bbd7438c8b.filesusr.com/ugd/ac612b_98fdddca4a08442a80e860da5f6b9fa5.pdf?index=true
    • https://uploads.strikinglycdn.com/files/783acdf8-7e88-4004-94e5-8952bcdfa9c2/what_is_the_default_password_for_lorex_cameras.pdf
    • https://s3.amazonaws.com/tirimofufemukat/kokumixupebimu.pdf
    • https://uploads.strikinglycdn.com/files/a43d506d-6f8a-4b08-8b14-65c2600e5643/zebra_gk420_default_ip.pdf
    • https://uploads.strikinglycdn.com/files/259142b6-2481-422a-8a59-70eabddab9e5/life_fitness_elliptical_x1.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e58b.bin
ab3da0b0b82624240dc542a092af1153f9f038048b77dc9f8b995b7f320ac7f5
pdf-font-stream PDF embedded font (sfnt) at offset 0xE58B 5392 bytes
font_01_sfnt_off0000f7dc.bin
d73b9c8ef88c3ec2521ee419ae9edab8dee35fe65dcf61e617c13afe9a0c6523
pdf-font-stream PDF embedded font (sfnt) at offset 0xF7DC 20172 bytes