Malicious PDF — malware analysis report

Static analysis result for SHA-256 cca93db42ed908f6…

MALICIOUS

PDF

85.5 KB Created: 2021-03-20 02:41:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 00cc16d17ee4d301d0246dfb7ff7cdd1 SHA-1: 18de1d7a600c3dbf304a1c7eafe2bc3c90903727 SHA-256: cca93db42ed908f6730516d544a24f4b0b04ac0bb3f687404a3ffbd277ad3966
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with one pointing to a suspicious URL associated with phishing. ClamAV and ML classifiers flagged this PDF as malicious, specifically as a phishing trojan. The presence of embedded URLs and the overall structure suggest an attempt to redirect users to a malicious site, likely for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=safe+haven+adt+hiring
    • http://mists.space/modal_verbs_exercises_multiple_choice_with_answersyxsy2.pdf
    • http://ellmax-site.xyz/xudotofahikuo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/sesijesule/state_space_representation_in_controllable_canonical_form.pdf
    • https://a9864912-ad24-422b-99f3-2d90f7703507.filesusr.com/ugd/d6af85_6fc95fb773894d5cbac067bd71adcceb.pdf?index=true
    • https://73856814-13bb-4d44-aeaf-752cce6ba6bd.filesusr.com/ugd/a0d21a_2dfb5362a79a4f468eddc8e34c1a3a9a.pdf?index=true
    • https://s3.amazonaws.com/tesapibebujep/angular_json_form_editor.pdf
    • https://uploads.strikinglycdn.com/files/08332975-aa85-4758-9133-3a740bc57f57/77846179220.pdf
    • https://s3.amazonaws.com/wipotegadodorek/bixew.pdf
    • https://e1cf253b-b3af-4135-a675-1c3c021177f9.filesusr.com/ugd/111c46_2ded4935cd174dd78bd8895983b43ac5.pdf?index=true
    • https://s3.amazonaws.com/takateg/alphabet_cursive_writing_free.pdf
    • https://fc060a1e-8c1d-4b7d-bafd-75f79d4c6355.filesusr.com/ugd/c0a468_4bfd84c4b914448aafd30a7c120e94ee.pdf?index=true
    • https://uploads.strikinglycdn.com/files/2bfb2698-af04-44b0-9f94-0b5273b910a7/61144340247.pdf
    • https://748f1d53-d141-46c1-926a-d14fc69713a3.filesusr.com/ugd/e3ed1f_a96bbf58ee00401e8637b6c603751a0b.pdf?index=true
    • https://24451074-f53b-4065-993c-779ba3957988.filesusr.com/ugd/0ae25f_ee3544a44c204b6598709c69f8fd5d15.pdf?index=true
    • https://bcbc83ff-a82b-4234-bf1d-c69e8cae54d5.filesusr.com/ugd/057c82_424afb98de7f467481a8937f3f2c8587.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fe9a.bin
ca0fef01f9c54a533bb159b2bc359dc625cc2964012f2ace5a304b3101828f2a
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE9A 5120 bytes
font_01_sfnt_off00011002.bin
64a0bbed4904ef6d3dc0d2caa69355f2bf384e0b92a09e472356ba82028dc329
pdf-font-stream PDF embedded font (sfnt) at offset 0x11002 4700 bytes
font_02_sfnt_off0001218e.bin
0d07a51493d35d4210c7a48b1f94b48109f646964eda1fe2ea78883e4da369e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x1218E 11612 bytes