Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa3361923b2f09ae…

MALICIOUS

PDF

83.7 KB Created: 2021-03-18 03:11:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2e5e048d31e4fa45fd7e56129a223235 SHA-1: 5c7f00ddf6bdf68c87e28a20182c107e9f075fda SHA-256: aa3361923b2f09ae705c1b616a0447275317dfeac23aac27f8b1eeace3d92a9a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for link farms or phishing lures. The ML classifier and ClamAV detection strongly indicate malicious intent, specifically identified as a phishing trojan. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic suggest the primary goal is to redirect users to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=classroom+observation+form+for+students
    • https://kumajevebak.weebly.com/uploads/1/3/1/8/131856027/rinikusipe.pdf
    • http://tijudozi.scienceontheweb.net/bagifojowemapa.pdf
    • http://housefashion.ru/my_car_runs_lean_at_idlezn10j.pdf
    • https://cdn.sqhk.co/xurunesijud/higgyie/rotator_cuff_pain_location.pdf
    • http://crawlmqyu.space/952323261624atat.pdf
    • http://car-test.pro/residoxosajifamenixalejtvyf.pdf
    • https://zejanedigerexig.weebly.com/uploads/1/3/4/7/134757062/peribowotixize.pdf
    • https://fogasofimoxor.weebly.com/uploads/1/3/1/0/131071298/3724783.pdf
    • http://losqutoq.online/filing_a_police_report_online_las_vegas9uo4t.pdf
    • http://itanah.space/australian_masters_rowing_championships_2019_results8k8qs.pdf
    • https://cdn.sqhk.co/pixazizaze/hhZjhhf/pozedesejazuvevero.pdf
    • https://vokefepafox.weebly.com/uploads/1/3/4/3/134333292/sujuno.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/72c809b2-c1b3-4f84-b51b-c24274fe0a14/96872437944.pdf
    • https://uploads.strikinglycdn.com/files/79619bd1-41cc-42fd-81f2-23a93575b38a/punujis.pdf
    • https://uploads.strikinglycdn.com/files/36386dbe-0b01-4ad8-bdad-99783d786450/bulovugakap.pdf
    • https://uploads.strikinglycdn.com/files/6cb8a7b7-7844-4c91-bcf3-436cf1245ae2/power_pressure_cooker_xl_instrukcja_obsugi_po_polsku.pdf
    • https://uploads.strikinglycdn.com/files/0080b221-c669-4b6c-84c0-b4b4b73b2700/jokewabapibubanonovolamif.pdf
    • http://kifesafijupesob.onlinewebshop.net/every_mans_battle_book_summary.pdf
    • http://jisunopesaluzi.atwebpages.com/what_is_lean_in_agile_methodology.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010a8d.bin
a142c821b39857b0cf6973b20c47963b6b234de36100dbfcb71cd86b89df1564
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A8D 5160 bytes
font_01_sfnt_off00011c04.bin
f6868b0032e38bdeb2125c79e17177002d0c0e7afd420fd1fc8cb3bce18ab745
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C04 11044 bytes