Malicious PDF — malware analysis report

Static analysis result for SHA-256 779cc17829e50d07…

MALICIOUS

PDF

76.6 KB Created: 2020-12-28 05:30:02 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2c926fbf4b99557bd109e45f78d15334 SHA-1: 6e880fb903a1cc865712dd2161e49a9128a73803 SHA-256: 779cc17829e50d079253e7c337af152cab0ed12bd6a8801d1d6f5e83105c3a0f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document exhibits characteristics of a link farm, containing a high number of external links pointing to various PDF files hosted on external services. The ClamAV detection and ML classifier strongly indicate malicious intent, likely for phishing or distributing further malware. While no scripts were explicitly extracted, the PDF structure and numerous external links suggest an attempt to lure users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/strik?utm_term=flippy+bottle+extreme+online
    • https://dugesadodi.weebly.com/uploads/1/3/1/1/131164249/010ceeaf450cd6.pdf
    • https://cdn-cms.f-static.net/uploads/4375886/normal_5fe7d8e03263a.pdf
    • https://mexasazage.weebly.com/uploads/1/3/4/5/134513067/bulokasomazepe-vowutoxomuda-pewidazafagij-rozixa.pdf
    • https://cdn-cms.f-static.net/uploads/4366628/normal_5fbcca0f65749.pdf
    • https://someradajisifu.weebly.com/uploads/1/3/4/6/134669983/6849487.pdf
    • https://cdn.sqhk.co/gadukupuwe/VjSGibv/67111559837.pdf
    • https://varozuwibudod.weebly.com/uploads/1/3/4/3/134327914/f74261c.pdf
    • https://cdn-cms.f-static.net/uploads/4459929/normal_5fb2c3ce1ff6d.pdf
    • https://fekogekakoxoki.weebly.com/uploads/1/3/4/6/134625435/rurijepa.pdf
    • https://cdn-cms.f-static.net/uploads/4376125/normal_5fc0c04827f40.pdf
    • https://jinobodusere.weebly.com/uploads/1/3/4/7/134722577/df926.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d325.bin
7c70668db034db5adfa22b43a24fb1fc78eb4eb52a2d5c06d330b4198f81bf08
pdf-font-stream PDF embedded font (sfnt) at offset 0xD325 4840 bytes
font_01_sfnt_off0000e38a.bin
b672ed32057b611730be586441f877a1b206a236b78c91f14c1564547a1c78c7
pdf-font-stream PDF embedded font (sfnt) at offset 0xE38A 2188 bytes
font_02_sfnt_off0000ed90.bin
bf7cd7aaeb4b6d3a3519565f9b0331321874d01089a865b3f5d980bfa4ce1d98
pdf-font-stream PDF embedded font (sfnt) at offset 0xED90 9912 bytes
font_03_sfnt_off00010faa.bin
f6e0f4a25f18a144688c6b7f40519a5efc98c72643b9054f89526e396d9b459d
pdf-font-stream PDF embedded font (sfnt) at offset 0x10FAA 16144 bytes