Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa764e5217aacc2c…

MALICIOUS

PDF

79.4 KB Created: 2021-03-18 12:20:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9bdbe0b74d45d23281dcb30dfce4b8e0 SHA-1: 21a381fa6e8b72fca331188b100c827e47663e12 SHA-256: aa764e5217aacc2cd28b353451febe1d401777b6fe0507df339c9c50e1c9d280
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The file is a PDF that contains a link farm and is flagged by ClamAV as Pdf.Phishing.Trojan. The heuristic 'SE_ADVANCE_FEE_SCAM_LURE' strongly suggests the document's content is designed to trick users into a scam. The embedded URL points to a domain associated with malicious activity, likely serving as the initial lure for a phishing or advance-fee fraud scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/strik?utm_term=the+remains+of+the+day+summary+pdf
    • https://cdn.sqhk.co/retirijozi/ghBihEy/93029593977.pdf
    • https://cdn.sqhk.co/sozivowemin/Ejjjghb/mardi_gras_color_block_shirt_wholesale.pdf
    • https://cdn.sqhk.co/lorotukogof/7ZKHiaT/jungle_adventure_free_online_game.pdf
    • https://cdn.sqhk.co/tawunipufop/2ghVice/redcon1_mre_bar_canada.pdf
    • http://desenusexewu.iblogger.org/84952350110.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/2699c2e7-ee97-4cfa-84eb-e83c8b57eb63/69978377550.pdf
    • https://uploads.strikinglycdn.com/files/9684d00f-7235-4105-9648-9f0efd46d6a2/86444297464.pdf
    • https://uploads.strikinglycdn.com/files/b854410f-5beb-4d0d-a0cb-2c5f95d6588b/under_the_dome_season_2_episode_1_free_online.pdf
    • https://cccd2283-d272-450a-840b-6541230ebad2.filesusr.com/ugd/5de1df_f4ea3d57ba544d8ba6f195502c98461a.pdf?index=true
    • https://3edbbcf3-b5b1-446e-9630-835d38fa79e0.filesusr.com/ugd/6908d7_4b2a2ad337994bd2baf2253b6bde9650.pdf?index=true
    • https://uploads.strikinglycdn.com/files/c15fda5a-e395-431f-adb2-b945e2ac732b/dell_precision_m4600_launch_date.pdf
    • https://8909b315-4d59-4940-aabf-0fdaa532e0ad.filesusr.com/ugd/4542d9_c3c6da1109b447b4964c68facfcd96ce.pdf?index=true
    • https://cfecb619-c0f5-418d-ae9d-b1147643389f.filesusr.com/ugd/4cd51e_795d4ddb844d411f8600f537af344007.pdf?index=true
    • https://a2214900-82f6-4ed5-a432-d5ffd14110fa.filesusr.com/ugd/306b6b_66844a8ac5394af697de898749488375.pdf?index=true
    • https://c63ca81c-6df4-4ec3-bc2e-8508f29a6879.filesusr.com/ugd/d48fe3_0fe936f5bc4c40e994a9e910852bf29e.pdf?index=true
    • http://xanojeja.rf.gd/grammar_for_english_language_teachers_download.pdf
    • http://fegumipidibig.rf.gd/59915288631.pdf
    • https://e8e87dc5-637d-47ba-9de6-e7d98d123d78.filesusr.com/ugd/a69a03_f6afb21b74ab40dfa76c545fa95b4312.pdf?index=true
    • https://uploads.strikinglycdn.com/files/02da4803-b82a-4c5e-a76d-67e11286ddf4/programming_comcast_remote_for_tcl_tv.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f986.bin
2510e1fddfb3e2ee3e983d2f7c2b107bf33ff66bc93e66fa5d71e3434a971d1b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF986 5300 bytes
font_01_sfnt_off00010b66.bin
8f4c738882f4c5bae81fe083d467fddf62139d55f450d86a4b93cd2ba6d19d66
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B66 10812 bytes