Malicious PDF — malware analysis report

Static analysis result for SHA-256 aaf288d42c7912e0…

MALICIOUS

PDF

90.0 KB Created: 2021-03-29 14:50:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5e47c63a77553d6c85240ee4fed75c23 SHA-1: 68a3fbf9c6fec2cf5696063df5fe4e1ab6eca983 SHA-256: aaf288d42c7912e0499b16ac9ed7c1448a2267f06e6aebd60e48356944d81357
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that exhibits characteristics of a link farm, with numerous external URLs pointing to other PDF documents. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically phishing. While no scripts were directly extracted, the PDF structure and the presence of external links suggest an attempt to redirect users to malicious sites or download further payloads, aligning with spearphishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9572

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dugedepap.ru/award?keyword=developing+assertive+communication+skills+pdf
    • http://tevopose.66ghz.com/57583893622.pdf
    • https://cdn-cms.f-static.net/uploads/4488572/normal_5fd2dded3cf66.pdf
    • https://bopilopuneliniw.weebly.com/uploads/1/3/5/3/135304065/891779.pdf
    • http://minosiw.22web.org/wowoluvojuvuli.pdf
    • http://jedugefipevama.iblogger.org/starcraft_brood_war_battlenet.pdf
    • https://popokafiri.weebly.com/uploads/1/3/1/4/131437291/3455340.pdf
    • https://jilukixewe.weebly.com/uploads/1/3/4/0/134042659/fezebe.pdf
    • https://fatononatigomun.weebly.com/uploads/1/3/4/8/134846471/8826685.pdf
    • https://cdn-cms.f-static.net/uploads/4470040/normal_5fd3bd05b471c.pdf
    • https://wamurereleveti.weebly.com/uploads/1/3/5/3/135392703/rupuvesawa.pdf
    • https://cdn-cms.f-static.net/uploads/4384150/normal_5fd192d5d3b0d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/resixexi/jofisogob.pdf
    • https://s3.amazonaws.com/pusori/asphyxia_piano_sheet.pdf
    • https://s3.amazonaws.com/dowavelaxam/77639451478.pdf
    • https://s3.amazonaws.com/vukujidor/cemu_breath_of_the_wild_install_guide.pdf
    • https://s3.amazonaws.com/sesafefanulokam/rational_function_transformation_equation.pdf
    • http://folixuk.rf.gd/dajewirimapume.pdf
    • https://s3.amazonaws.com/xoxaneral/big_chungus_song.pdf
    • https://s3.amazonaws.com/pirosisob/72237303079.pdf
    • https://s3.amazonaws.com/jefazaxal/40066074715.pdf
    • https://s3.amazonaws.com/sugowubuf/xemofibuzaluvaz.pdf
    • https://s3.amazonaws.com/fakuguvil/ye_bhagwa_rang_dj_king.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012b5b.bin
001a000307586a823fc64c8fb3cf429bccf3c249222789d1bbe939108d4e9ac3
pdf-font-stream PDF embedded font (sfnt) at offset 0x12B5B 5600 bytes
font_01_sfnt_off00013e6e.bin
79cacaa09fdac913bf928166ea5ca98dc05cd721cd690d1a6ccb2f84dde8b0e9
pdf-font-stream PDF embedded font (sfnt) at offset 0x13E6E 10552 bytes