Malicious PDF — malware analysis report

Static analysis result for SHA-256 417ba65b24381b67…

MALICIOUS

PDF

126.3 KB Created: 2022-06-29 20:36:43 Authoring application: Amended Sales Tax Return Missouri durring (via FPDF 1.82) First seen: 2022-07-15
MD5: 67c8f7763463a865f64b58bae6b4eba0 SHA-1: e2c2d77bd48d46b503ba5520a1966f90c4b4d438 SHA-256: 417ba65b24381b67fbccbb7ed177f35b9ceac7c445c81f08e3d426a6d2f0ea9f
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document employs a lure of an 'Amended Sales Tax Return' to trick the user. It contains multiple invisible and repeated links pointing to the domain 'completespcr.site', which likely serve to download a secondary payload. The presence of invoice and payment-related language further supports the phishing pretext.

Machine Learning

  • Nyx PDF Classifier clean score 0.0014

Heuristics 3

  • Invisible/repeated PDF links deliver payload file critical PDF_REPEATED_PAYLOAD_LINK_LURE
    PDF uses invisible link annotations and points to a direct payload download. Repeated invisible links or lure-like payload names such as document/unlock/verify archives match malware-delivery PDF carriers where the page is only a prompt and the real payload is fetched from the linked URL.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://completespcr.site/Amended-Sales-Tax-Return-Missouri/pdf/copycentralga.com
    • http://completespcr.site/Amended-Sales-Tax-Return-Missouri/doc/copycentralga.com
    • https://copycentralga.com/wp-content/uploads/formidable/2/does-retirement-savings-recommendation-include-home-ownership.pdf
    • https://copycentralga.com/wp-content/uploads/formidable/2/free-wood-flag-plans.pdf
    • https://copycentralga.com/wp-content/uploads/formidable/2/eset-email-protection-by-protocol-filtering-is-non-functional.pdf
    • https://copycentralga.com/wp-content/uploads/formidable/2/charu-c-aggarwal-recommender-systems-pdf.pdf
    • https://copycentralga.com/wp-content/uploads/formidable/2/customer-satisfaction-survey-industry-standards.pdf
    • https://copycentralga.com/wp-content/uploads/formidable/2/saxe-coburg-and-gotha-proclamation.pdf
    • https://copycentralga.com/wp-content/uploads/formidable/2/air-pollution-modeling-and-its-application.pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_026_off0001ec39.bin
43b13684882d332187dbe2691d5e4f64c33a98e381a4dc2316374ba1b923b47c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1EC39 76950 bytes