Malicious PDF — malware analysis report

Static analysis result for SHA-256 61ec68f1d26137b2…

MALICIOUS

PDF

78.5 KB Created: 2021-04-06 23:52:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3fb0031905b8324a58779e44d3346fb4 SHA-1: aab4fb6873120d0361e0ae8cf4316e4ed60b79db SHA-256: 61ec68f1d26137b270961d3478f04e1cb7b38790ca79bcf485c9336212ebdcda
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files. One of these links, https://botokaw.ru/123?utm_term=ppl+flight+test+guide+pdf, is directly embedded and flagged as an external URI. ClamAV also detected the file as Pdf.Phishing.Trojan, indicating a phishing or malicious intent. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=ppl+flight+test+guide+pdf
    • http://zezasasipow.iblogger.org/49305194655.pdf
    • https://cdn.sqhk.co/xewafazuk/Ohdjchg/lomogagipajazigenew.pdf
    • https://cdn.sqhk.co/wugunifikezu/a0iigfD/99959893663.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/donarepemi/troy-bilt_horse_tiller_service_manual.pdf
    • https://s3.amazonaws.com/miwolezedubujoz/66196824568.pdf
    • https://5366dd3f-28a3-4342-b8e5-5bed86455aec.filesusr.com/ugd/a92322_d3d12aabaf224402afbb8b21e0e20c2b.pdf?index=true
    • http://guzupuxidulijak.rf.gd/83043867097.pdf
    • https://37976aa0-f55f-47d3-847a-8d185b13ebf6.filesusr.com/ugd/1d6212_ebde349af5ce481b98d12ecf84ce1940.pdf?index=true
    • https://s3.amazonaws.com/kotenu/unicorn_electronic_dartboard_manual.pdf
    • http://mutunibe.rf.gd/wagiv.pdf
    • https://s3.amazonaws.com/supefujoxopubu/what_color_goes_with_navy_blue_shirt.pdf
    • https://2489a575-72f7-492f-b117-28cfe4a4d2a3.filesusr.com/ugd/d81705_5cced4cc04754076a11199146f7c320e.pdf?index=true
    • https://s3.amazonaws.com/xoguwavosuje/aimbot_gta_san_andreas_multiplayer.pdf
    • https://s3.amazonaws.com/mupukesunobaga/poxolivudibipabajuritika.pdf
    • https://a9d1d3ec-13fa-4b7e-abe1-abe2c2ba1301.filesusr.com/ugd/f83029_4553620f703c4e8e805d9567fab0e63e.pdf?index=true
    • https://d4508431-0eee-4913-ac2a-2ec907ed9b18.filesusr.com/ugd/12daa7_905d6c9c608849c490af9575c1bfa9b0.pdf?index=true
    • http://nefijeniwipe.epizy.com/baxi_boiler_timer_manual.pdf
    • https://8a6b9437-e7f2-49d7-8c24-351b272aa67a.filesusr.com/ugd/b18e4d_995314b3f1c24589ad27a75eab87a10c.pdf?index=true
    • https://49d0234c-aae4-472d-9cb9-6192e9e03354.filesusr.com/ugd/a63595_da600309136d416d9d78257a2f45b2a8.pdf?index=true
    • https://20128683-61eb-4207-b985-d468b1a81fea.filesusr.com/ugd/0049ca_a7665e889a054339bd20e4f654b8c693.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f543.bin
8824703e744f85b728ce74821f4c4f4dc767c47f383ec76266befc1d62ee1c3a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF543 4996 bytes
font_01_sfnt_off0001064b.bin
d012906b345fb924b0be499d1dee51df344ee1e4d4d70f6217f20931cd99dd8c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1064B 11244 bytes