Malicious PDF — malware analysis report

Static analysis result for SHA-256 acca19aa28bb4845…

MALICIOUS

PDF

79.0 KB Created: 2021-05-17 21:03:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c89de305934b451ac43867299cf74540 SHA-1: 7d1dfc356d105f83cee002fc542b8d8dcebcbcb5 SHA-256: acca19aa28bb4845565f29ed177e7dcf4a2689c33144c217b4687992c24b50dd
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file flagged by ClamAV as a phishing trojan and by a machine learning classifier. It contains numerous external links, with heuristics indicating a 'PDF_SEO_LINK_FARM' pattern, suggesting an attempt to redirect users to malicious sites. While no scripts were explicitly extracted, the PDF structure and embedded URLs point towards a phishing or malware distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=klh+subwoofer+asw10-120
    • http://serviceforyou.site/harry_potter_y_el_misterio_del_principe_libro_resumenizhfl.pdf
    • https://cdn.sqhk.co/zewumabigige/gcPKdjg/42804602907.pdf
    • https://cdn.sqhk.co/tinulafi/JgiZheg/football_stickers_for_whatsapp_2020_21.pdf
    • http://dkmz1.club/etrex_20x_user_guidejk9zf.pdf
    • http://joriwolujuf.sportsontheweb.net/aspects_in_astrology_a_comprehensive_guide_to_interpretation.pdf
    • https://cdn.sqhk.co/govamopega/iarVhgf/the_last_survivors_game_poki.pdf
    • http://sfr-espace.best/21804982150k1ink.pdf
    • https://cdn.sqhk.co/memenewo/2hiojhS/gunowetiritewaso.pdf
    • http://ranking-se.com/life_skills_programs_for_students_with_disabilitiesi5lps.pdf
    • https://cdn.sqhk.co/bodegife/jbZheQw/ahsanullah_university_admission_form_2018.pdf
    • http://gamedv.design/9273705990levpe.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/kagedatabujo/irs_form_for_child_care_expenses.pdf
    • https://s3.amazonaws.com/rupatojuko/hippeastrum_planting_guide.pdf
    • https://aa4c2489-c93b-4667-afab-104bf5323bad.filesusr.com/ugd/8b49c6_9a4d30bf0ac04c119dcd60f78d13f408.pdf?index=true
    • https://c931c956-7f53-4e4e-96dc-27d7f003ba63.filesusr.com/ugd/b80c10_20ac9db6a0d8413ebda301237e7dda67.pdf?index=true
    • https://5902ff30-e651-486c-ac37-3e8383bfa78f.filesusr.com/ugd/f35da0_83ecbfe56e4441e69bcf7dbdcbd8ae70.pdf?index=true
    • https://bad3f395-1638-4667-b349-d6f934eeab49.filesusr.com/ugd/ed2d23_b8483ffd7507495f80867cbf6aa715df.pdf?index=true
    • http://wurebosuloxu.myartsonline.com/christmas_carol_lyrics_printable.pdf
    • http://nevabaza.atwebpages.com/45366819556.pdf
    • https://bff5fdab-9fd0-4670-908b-a1308bb5a9cb.filesusr.com/ugd/227d0f_39c153f4243c453eb522882c4c2a8632.pdf?index=true
    • https://s3.amazonaws.com/pewebopufupe/how_much_should_a_miniature_dachshund_weigh_at_2_months.pdf
    • https://9e28b13d-ef5c-4d18-821e-e071a8932918.filesusr.com/ugd/0b0738_8e49339eefd046dd898ffe68596d77f3.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f3e6.bin
02ce28b8fc6988d44788340b73972357f99846c686a855af03dc2f1c92766fc1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF3E6 5416 bytes
font_01_sfnt_off0001066c.bin
fc16737a8b232808fe82c9b6a2e0fe30f1183b98d0fa34b5f788b25d1412d840
pdf-font-stream PDF embedded font (sfnt) at offset 0x1066C 11272 bytes