Malicious PDF — malware analysis report

Static analysis result for SHA-256 06ac51348f32c646…

MALICIOUS

PDF

107.7 KB Created: 2021-03-11 12:45:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b2d4bb3f76e10b53e77599b1f1f9a60e SHA-1: 256fce5201affc6569a8fddc2137c478005d961a SHA-256: 06ac51348f32c646fcba52be37b1cf5865bdad7ab45cf1d2c26ccd98a34c31d9
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, with the primary URL being 'https://zajinet.ru/wix?keyword=rick+joyner+pdf+drive'. This behavior is indicative of a link farm or SEO manipulation tactic. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or distributing further malicious content. No scripts were extracted, but the PDF structure itself facilitates the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=rick+joyner+pdf+drive
    • https://cdn-cms.f-static.net/uploads/4471488/normal_6014deb38b83f.pdf
    • https://static.s123-cdn-static.com/uploads/4366316/normal_5ffb69657d0c0.pdf
    • https://cdn-cms.f-static.net/uploads/4392656/normal_6020fa97c3a68.pdf
    • https://cdn.sqhk.co/zexetiminav/sXjggXn/flightstats_historical_flight_data.pdf
    • https://cdn.sqhk.co/lifudidu/ifjehcd/69153238689.pdf
    • https://cdn.sqhk.co/bojojiweg/ebChggi/baker_business_3_premium_apk.pdf
    • https://static.s123-cdn-static.com/uploads/4375885/normal_5ffe4259dd14a.pdf
    • https://cdn.sqhk.co/laripikiwafo/vVWifjf/carnival_games_rental_los_angeles.pdf
    • https://cdn.sqhk.co/jilowepe/Wgmjjc6/73718453606.pdf
    • https://cdn-cms.f-static.net/uploads/4479210/normal_603cae68961ad.pdf
    • https://cdn.sqhk.co/vezukefuza/4ifjaTK/pc_games_multiplayer_free_download.pdf
    • https://cdn-cms.f-static.net/uploads/4484632/normal_603f7d56c397c.pdf
    • https://cdn.sqhk.co/pogezasamu/je9h8Pa/organic_fruits_and_vegetables_delivery_near_me.pdf
    • https://static.s123-cdn-static.com/uploads/4380545/normal_60039eef86ef2.pdf
    • https://cdn-cms.f-static.net/uploads/4368976/normal_60158d6dedd55.pdf
    • https://static.s123-cdn-static.com/uploads/4412889/normal_5fcb436545ea3.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://7f3dc8b3-869c-44c5-82eb-14ae88d57796.filesusr.com/ugd/dc4ca1_2ecfd31caa5943e494a00111443936ad.pdf?index=true
    • https://d5bea983-5bca-41ba-aae6-6b688785cc77.filesusr.com/ugd/9ec29b_70332253f4254538939282260cdaa22e.pdf?index=true
    • https://uploads.strikinglycdn.com/files/e2889c4c-57cc-4efc-b86f-d10d0e27cbb5/93419681107.pdf
    • https://uploads.strikinglycdn.com/files/afc5e43a-4065-4e21-b77c-985afea4d159/the_walking_dead_comic_volume_17.pdf
    • https://cfecb619-c0f5-418d-ae9d-b1147643389f.filesusr.com/ugd/4cd51e_b1c2168a38d34cd6a7235f6eeeed086c.pdf?index=true
    • https://a6f18165-9bfd-46c9-8f51-0ab50cd0b687.filesusr.com/ugd/265c7a_1cfcf089c1c64b3f8302aeb2bd8d35d8.pdf?index=true
    • https://1350f94c-8d6f-42b4-8351-24983ad6a49a.filesusr.com/ugd/4aae87_c4fadc185984410e93255158182d52d4.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00016b21.bin
7032a5aefc5a736e3ff09b1ce7aa071eb74a4e4cedac5a639433d20fc4ce6aae
pdf-font-stream PDF embedded font (sfnt) at offset 0x16B21 5036 bytes
font_01_sfnt_off00017c7a.bin
0f11c493562b2cba0452f67e28427f3ff2219e4c1a12171c3f289d2af2c5701e
pdf-font-stream PDF embedded font (sfnt) at offset 0x17C7A 10908 bytes