Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa180a7d3853fd60…

MALICIOUS

PDF

75.3 KB Created: 2021-03-29 14:23:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 65e4095c1c6b8ccfff643a961b56c940 SHA-1: e1e76e7b27d98858da625a2c1bd4ad2436d4ccc1 SHA-256: aa180a7d3853fd605751b694f59ae1a890d7c52bd85c9a836c2602310379949b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, characteristic of a link farm or phishing lure, with one URL specifically mentioning 'parts of speech exercises with answers doc'. ClamAV detected this as Pdf.Phishing.Trojan, and ML classifiers also flagged it as malicious. The presence of embedded URLs and the overall structure strongly suggest a phishing or malicious redirection attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=parts+of+speech+exercises+with+answers+doc
    • https://static.s123-cdn-static.com/uploads/4449395/normal_5fca98e49ce50.pdf
    • https://cdn.sqhk.co/vizakifito/MyjeYIn/manor_cafe_cheat_unlimited_stars.pdf
    • https://cdn.sqhk.co/dojagomudek/bsJsggA/47254160023.pdf
    • https://cdn.sqhk.co/pemejurove/cTiccii/basketball_stars_of_american.pdf
    • https://cdn.sqhk.co/kakapoxavu/fhwqu0C/30081252625.pdf
    • https://cdn-cms.f-static.net/uploads/4495551/normal_6015852715798.pdf
    • https://cdn.sqhk.co/kunimoxifagi/DgjJ1xa/exonerated_example_in_a_sentence.pdf
    • https://cdn.sqhk.co/lewuravasu/VRA1fOg/surah_shams_full.pdf
    • https://static.s123-cdn-static.com/uploads/4451954/normal_5fc9873691774.pdf
    • https://cdn.sqhk.co/dafisuwikib/jifjOid/15127408910.pdf
    • https://cdn-cms.f-static.net/uploads/4382781/normal_60283a0a19223.pdf
    • https://cdn-cms.f-static.net/uploads/4453328/normal_601e534e00cec.pdf
    • https://cdn.sqhk.co/nobutowug/805Yshe/grass_cutting_machine_for_sale_in_durban.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/rowubunak/pemudolalutavutumevazude.pdf
    • https://a943cdc4-551e-4fd6-8842-bb1c82e441e2.filesusr.com/ugd/a0303e_ed726905d7e9404ca61d8caba38bbe8b.pdf?index=true
    • https://s3.amazonaws.com/forupokisip/52964345566.pdf
    • https://00eaa6b3-f026-4720-b00f-fafb40066352.filesusr.com/ugd/d498be_0421068ccc964e75a01726819f994ecf.pdf?index=true
    • https://6f465708-eb37-4ee2-8658-ebeec6cd93ea.filesusr.com/ugd/4bb103_a3ec8abd9edd4b62b9890f513203aa4c.pdf?index=true
    • https://s3.amazonaws.com/wusigipufuvowix/beauty_parlour_camera_apps_ing.pdf
    • https://7043ee2c-bc2d-4d46-b82c-b0075177c1aa.filesusr.com/ugd/f862b5_8ff95e24b5f74c26a8dd1b62aa89cfb3.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e557.bin
2c239870128b3e3f6c37d33d9f3dd08a37161b2d802f5fac4c4352372b38fd48
pdf-font-stream PDF embedded font (sfnt) at offset 0xE557 5372 bytes
font_01_sfnt_off0000f7ae.bin
a0800351972233c25172e521f7cb01015019c09684991f25427ea5b236e5953c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF7AE 11128 bytes