Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff6256b30b5cbb7b…

MALICIOUS

PDF

78.9 KB Created: 2021-05-26 06:50:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8aebf5e902849cd5a8e3da00a253c084 SHA-1: 771d8f7370123d49ccf10e17e1f3723d60200625 SHA-256: ff6256b30b5cbb7be324919fe1d0d10df4ad2f73203e8d8e0bc377ff531d9d1a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are likely part of a link farm designed to attract traffic or host malicious content. The primary detected URL, 'https://dafemum.ru/strik?utm_term=how+to+get+unlimited+farm+bucks+in+farmville+2', suggests a lure related to in-game currency, indicative of a phishing or scam attempt. The ML classifier and ClamAV detection strongly support the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/strik?utm_term=how+to+get+unlimited+farm+bucks+in+farmville+2
    • https://mexavabawidusa.weebly.com/uploads/1/3/4/3/134375000/1bfcb5b2fba.pdf
    • https://dorikorojuj.weebly.com/uploads/1/3/3/9/133987202/bogupixitame.pdf
    • https://boxizegovabore.weebly.com/uploads/1/3/1/3/131379280/896901.pdf
    • https://gamupizesusaza.weebly.com/uploads/1/3/1/3/131398140/larugodumovedin.pdf
    • https://dotaterezisal.weebly.com/uploads/1/3/4/7/134771172/5705584.pdf
    • https://mamiwego.weebly.com/uploads/1/3/4/3/134315995/6871029.pdf
    • https://nalovitifa.weebly.com/uploads/1/3/4/6/134600698/5036349.pdf
    • https://xamegazu.weebly.com/uploads/1/3/4/4/134440804/gizizezepe.pdf
    • https://kujakaxu.weebly.com/uploads/1/3/5/3/135347331/gazedekened.pdf
    • https://tinuwese.weebly.com/uploads/1/3/5/3/135300683/4401665.pdf
    • https://xedukigujidazan.weebly.com/uploads/1/3/4/5/134512451/komevatu_pilenibaxe_parapazafima_zuvisuv.pdf
    • https://revoninutilira.weebly.com/uploads/1/3/5/3/135338282/a72662622b4.pdf
    • https://dorixakogika.weebly.com/uploads/1/3/6/0/136051108/2915094.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/6ab602b9-78b5-47f3-8ce2-62c734e3a19e/65561783150.pdf
    • https://s3.amazonaws.com/luworizesupox/latin_american_independence_movements_answer_key.pdf
    • https://s3.amazonaws.com/juliziwojatige/android_action_bar_example_source_code.pdf
    • https://s3.amazonaws.com/xopugup/40371001281.pdf
    • https://uploads.strikinglycdn.com/files/8d4d26d4-e3d5-4aba-a361-d2bbf7876609/6799611373.pdf
    • https://s3.amazonaws.com/pululusodogi/72660771232.pdf
    • https://s3.amazonaws.com/dorulusof/ca_intermediate_course_books.pdf
    • https://s3.amazonaws.com/kudufigunabi/live_nettv_4._5._1_apk_uptodown.pdf
    • https://s3.amazonaws.com/bokexizometun/asperger_livro.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f127.bin
cd7b9c3c55c7927e4263d9dbd8655a424db9aa90476bc6ba22c98511c6d3f272
pdf-font-stream PDF embedded font (sfnt) at offset 0xF127 5792 bytes
font_01_sfnt_off000104eb.bin
f6a53ed10063bdfd18a5cac39e6d0b656e00770e26dee03939f4fbbff9deed51
pdf-font-stream PDF embedded font (sfnt) at offset 0x104EB 11496 bytes