Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc51a0dc5ece4820…

MALICIOUS

PDF

83.5 KB Created: 2021-04-03 20:53:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 026227fdc0ab5fc83139f34e25107157 SHA-1: 02d414c12958031e519e912b01ef8f7f00a5976c SHA-256: cc51a0dc5ece4820f9989c2756f84136c2f5d9b85ced6a721c08d0ec9badf33a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a primary focus on a URL that appears to be part of a link farm designed to attract search engine traffic. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution. The embedded links and the nature of the heuristic firings suggest an attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/award?keyword=bread+maker+cookbook+pdf
    • https://fukuperuka.weebly.com/uploads/1/3/4/8/134883813/rutezegijas.pdf
    • https://rudunusom.weebly.com/uploads/1/3/4/6/134602981/1471056.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/doxifuba/24749725539.pdf
    • https://s3.amazonaws.com/rewepalazamiso/xururafagudaniwomid.pdf
    • https://uploads.strikinglycdn.com/files/23971184-edf1-4026-982d-844ccb9d0a61/how_to_get_veteran_status_on_drivers_license.pdf
    • https://s3.amazonaws.com/winumigutam/jotukixikatefuvojepus.pdf
    • https://96ea5dd8-6962-4d57-b29c-fb233a715e3b.filesusr.com/ugd/ac3463_8fd96cd31e5f4ab6a3f3e7b41bd18647.pdf?index=true
    • https://s3.amazonaws.com/pibabopuduj/bed_sheets_asda_george.pdf
    • https://44407f20-7244-4107-9544-84d8151b6f9a.filesusr.com/ugd/8508de_97a9cbff78214dd29d5b0f07715ad303.pdf?index=true
    • https://0dd0cd87-80d3-4eb5-b9c6-73c43c3a6fca.filesusr.com/ugd/f0b6b3_ac66884151bc4264ad08dc1396831104.pdf?index=true
    • https://167c8e7b-8160-49a2-a88e-f26749d647c8.filesusr.com/ugd/1ad47d_e255b05e902e40d78aff63e9682c4748.pdf?index=true
    • https://8dcf3d85-40eb-4350-b789-ae6ac2c46e24.filesusr.com/ugd/21d17a_15abc1a29a1740659fdd30657eba5c8b.pdf?index=true
    • https://369206df-e466-4f8f-9771-850d1edb33c5.filesusr.com/ugd/8fd5dc_508ede115753493d92c04e9954044415.pdf?index=true
    • https://s3.amazonaws.com/wurivuve/75085352380.pdf
    • https://uploads.strikinglycdn.com/files/37390a18-a7a5-4e76-9b62-17fb7d5cc8c9/tuwugamadijaj.pdf
    • https://uploads.strikinglycdn.com/files/9cec05c5-05fc-46e3-9969-882c62f67907/17076280366.pdf
    • https://s3.amazonaws.com/jizubisetebof/kikafefusivirawi.pdf
    • https://856cb5e6-6c81-45ce-9604-b57907a15cd2.filesusr.com/ugd/cc3ca9_713aab47136448d595062a76a311d74e.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001087e.bin
96ae79a3a5c632ef3be225bc3e1f7cf7d101d6f82b881fa3551d25765ed1f956
pdf-font-stream PDF embedded font (sfnt) at offset 0x1087E 5344 bytes
font_01_sfnt_off00011a9a.bin
13402907963c0a5d4181bc1d5eeb9ba1b27e310f67991608b054ff3fb09d9768
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A9A 11284 bytes