Malicious PDF — malware analysis report

Static analysis result for SHA-256 acdfdcb9d69ee0fc…

MALICIOUS

PDF

79.8 KB Created: 2021-03-15 05:02:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6508dfbf870341d38e61961b7f11f219 SHA-1: 76cecbcb7932260e24c6bde6e7c7877665cc58f0 SHA-256: acdfdcb9d69ee0fc6f38b04672c1589f8d28c9263405ec2a93a40c8eba20d542
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains an embedded URI pointing to 'dafemum.ru', which is likely a phishing lure. The PDF also exhibits characteristics of a link farm, with numerous external links, suggesting an attempt to distribute malicious content or engage in SEO manipulation for malicious purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/award?keyword=modern+slavery+in+africa+pdf
    • http://muwiduvepobuz.mygamesonline.org/lotelaguzerobukufijotowa.pdf
    • http://jesofoma.getenjoyment.net/united_colors_of_benetton_competitors.pdf
    • https://cdn.sqhk.co/zidenesek/3K8PDje/formula_unlimited_racing_mod_apk.pdf
    • https://cdn.sqhk.co/zuxosutuku/Hhchgje/while_true_learn_review.pdf
    • https://cdn.sqhk.co/wubofuse/cfiHnXQ/95351653835.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vukumesoj/obusforme_chair_replacement_parts.pdf
    • https://s3.amazonaws.com/tiduro/fepesezorigaxez.pdf
    • https://7a48fde5-f9d1-4ce4-84a2-8b156d245d18.filesusr.com/ugd/8127dd_d0869791ace246f0b5e322d740e4ca08.pdf?index=true
    • https://s3.amazonaws.com/tipikaxe/airserver_xbox_one_android.pdf
    • https://s3.amazonaws.com/tejuvonixag/b._d._a_full_form.pdf
    • https://s3.amazonaws.com/lomogas/avatar_full_game_free.pdf
    • https://s3.amazonaws.com/tarajix/computational_fluid_dynamics_books.pdf
    • https://234d5d8d-19c9-4cab-a884-dd0775662658.filesusr.com/ugd/fb7225_ba1e2b6d846d462b9aee076807e6920d.pdf?index=true
    • https://s3.amazonaws.com/kobivimelelo/telireguligar.pdf
    • https://s3.amazonaws.com/dewazewokib/rarabomozij.pdf
    • https://s3.amazonaws.com/boxujetanonikuv/66611187959.pdf
    • https://s3.amazonaws.com/lodazojamuva/kowatobimup.pdf
    • https://db532842-334f-4efb-8993-e67ec8f20ff5.filesusr.com/ugd/bc5be3_a3c712894f4a4b61a7ecb4aaf9a4c7bb.pdf?index=true
    • https://s3.amazonaws.com/magapeguwabe/carbozinc_859_product_data_sheet.pdf
    • https://s3.amazonaws.com/legapatatezisa/economics_igcse_textbook_answers.pdf
    • https://e1ca4115-fb55-43f9-84f1-eaf814f8c83f.filesusr.com/ugd/18122d_04caec358f2a4d5bb2a17875df40fe4c.pdf?index=true
    • https://s3.amazonaws.com/mujevubutukoxu/aesa_radar_beamforming.pdf
    • https://s3.amazonaws.com/goviwigax/30405123471.pdf
    • https://18cb0a1d-3822-48a5-9ca0-56465202bc9b.filesusr.com/ugd/96564c_34a9059799304107b3dc98bad99c92ab.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f729.bin
160fb7a15469a16c1097c0dcbdd50d902828a75e07740167ea1bcaea91df4e43
pdf-font-stream PDF embedded font (sfnt) at offset 0xF729 5316 bytes
font_01_sfnt_off0001096e.bin
2ea9d2af1205a88968fb7e7415458ae796df8b7038248cd900e7f5c9c27980c8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1096E 11432 bytes