Malicious PDF — malware analysis report

Static analysis result for SHA-256 c64aaa19a68e3729…

MALICIOUS

PDF

110.8 KB Created: 2021-03-14 16:41:38 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8400527b28c7f17e114984fb562d3f51 SHA-1: 1c52af39a013892a3d3e9e3ea1c80ef8a024e632 SHA-256: c64aaa19a68e3729d7014d61094b2d299325b9e6e04287ae261ad70ea4c12c25
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO manipulation tactic. The embedded URL and the ClamAV detection further indicate malicious intent, likely phishing or hosting malicious content. No scripts were extracted, but the structure and heuristics point to a malicious PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9770

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/award?keyword=magazine+pdf+telegram+channel
    • https://cdn.sqhk.co/jobezivozuf/fU3R0SS/loudoun_now_obituaries.pdf
    • https://sewusadata.weebly.com/uploads/1/3/5/4/135401056/ba7869.pdf
    • https://rotarivinevi.weebly.com/uploads/1/3/4/5/134599250/777858.pdf
    • https://cdn.sqhk.co/buvaboda/ahbibge/fezadudigo.pdf
    • https://cdn.sqhk.co/gibebomesani/if9D37V/furemazojula.pdf
    • https://cdn.sqhk.co/litazujizime/7oImhWY/overkill_the_dead_survival_apk_mod.pdf
    • https://cdn.sqhk.co/lapefuxolu/jiAsiio/ziwugaf.pdf
    • https://povurumupun.weebly.com/uploads/1/3/4/8/134884194/7034576.pdf
    • https://cdn.sqhk.co/dadirowuj/ANhf20o/ninja_coffee_bar_cleaning_flush.pdf
    • https://cdn.sqhk.co/dokiladigana/a8myHRb/moto_g_power_price_philippines.pdf
    • https://cdn.sqhk.co/xezufulozuwo/cjf6gTF/95914158128.pdf
    • https://cdn.sqhk.co/petebeki/iijdgdu/rikujivajibisovatuja.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://37e0f79d-b0c1-4727-b76d-5b759c81288f.filesusr.com/ugd/9c66ff_a91c046ec0504010923f6e0a5497c7b4.pdf?index=true
    • https://uploads.strikinglycdn.com/files/c5c60354-f724-4317-b353-718cb9c7a7d7/timowubuwonigin.pdf
    • https://9907981b-0bc7-4fd3-a434-169f7cdadf42.filesusr.com/ugd/575363_49f8dc9f3d744038a1feda6539a62c10.pdf?index=true
    • https://b5c4f4dd-ae1f-4f6a-908c-f463551224e4.filesusr.com/ugd/dafd60_e366384fbb7544d58561b5d77a8a7831.pdf?index=true
    • https://6b5d12f1-3bbc-48af-9ddb-5430d2fe15e7.filesusr.com/ugd/3bf302_0d258c40f4834299bab30e5e8002ad42.pdf?index=true
    • https://63dbeab4-18c6-4677-a808-17cd77aec119.filesusr.com/ugd/963d80_d4d871f1e2d54758a7f121914a257405.pdf?index=true
    • https://3d5b2cfc-74f5-4c02-8466-0d369b02955c.filesusr.com/ugd/69b86f_e7c98dfbdf494d41bc37ef409d75d4f3.pdf?index=true
    • https://uploads.strikinglycdn.com/files/4441f6e1-cb8c-448c-8adb-3475c1a131c6/93049220503.pdf
    • https://uploads.strikinglycdn.com/files/4ff62dbe-0919-49b8-8971-75f0692da89c/memojiminoruverovuliv.pdf
    • https://9d349da1-218b-4b59-9e37-2a90cab56d40.filesusr.com/ugd/de9003_bce470f9580c476c8e51b8fe9f7b9440.pdf?index=true
    • https://uploads.strikinglycdn.com/files/52674aeb-733d-445c-805a-204c4dd776d1/8889122670.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f866.bin
52c3a75fb647145c916aee13f84f469d9be4ec97ccbdb755d1412f0911658698
pdf-font-stream PDF embedded font (sfnt) at offset 0xF866 3028 bytes
font_01_sfnt_off00010323.bin
d285300731c7aef718ddf2057e8cef957bf96a3fc582b65ff82a4d89af464e85
pdf-font-stream PDF embedded font (sfnt) at offset 0x10323 5444 bytes
font_02_sfnt_off00011594.bin
a81e6163156cba80c319bf517769d557737417e92940a87db2f1a7f3b364994b
pdf-font-stream PDF embedded font (sfnt) at offset 0x11594 10376 bytes
font_03_sfnt_off00013337.bin
786d62c2a94379ad88d3d9264bc606e37edfa288016dda0eedcb7fe5e80136bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x13337 12152 bytes
font_04_sfnt_off00015ccf.bin
bec218a71b51535ff4a62bdfc4334e1c104168c51eef68689c95079f658aa5c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x15CCF 17816 bytes
font_05_sfnt_off0001779f.bin
ac9df34758bc8b47276d3a8f64ec872d32c297f4a54602625e92bb9cfcb0e8cd
pdf-font-stream PDF embedded font (sfnt) at offset 0x1779F 19016 bytes
font_06_sfnt_off0001967c.bin
e5812e991a3439bdab68e8397277dd1621013afb5b40f7b0460a2cca404fd6e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x1967C 5188 bytes