Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a8996b96c72ac07…

MALICIOUS

PDF

127.9 KB Created: 2021-03-28 15:51:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: daf1a0f8cef85a11c64c35211ec9ea81 SHA-1: bd39ba2cbbe0d96b6ad8c39b07873a581396d1ff SHA-256: 0a8996b96c72ac07f43cfbf791ab84d40abf3b3841e767433330757b8e122c29
176 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a critical heuristic identifying it as a link farm. One prominent URL, 'https://zajinet.ru/wix?keyword=device+unlock+t+mobile+apk+hack', suggests a lure related to unlocking mobile devices, potentially for phishing or malware. The ClamAV detection and ML classifier further indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and link farm behavior are indicative of a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9734

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=device+unlock+t+mobile+apk+hack
    • https://virixodebusetij.weebly.com/uploads/1/3/1/3/131383575/dewexifukozazavinuda.pdf
    • http://tawaguf.scienceontheweb.net/zoology_textbook_class_12.pdf
    • https://runumoviw.weebly.com/uploads/1/3/4/8/134854062/tonuwid-vesaxe-golejebu.pdf
    • https://cdn.sqhk.co/baxijaxazixi/hdqogdx/httyd_school_of_dragons_wiki.pdf
    • https://bopovajo.weebly.com/uploads/1/3/5/9/135966354/kobujuvetesig.pdf
    • http://pofaduxiruk.getenjoyment.net/melalanusubesomowu.pdf
    • https://zubikuzo.weebly.com/uploads/1/3/1/4/131453486/4737904.pdf
    • http://rogijowop.sportsontheweb.net/pdf_to_word_converter_software_crack.pdf
    • https://wewopamutufufo.weebly.com/uploads/1/3/1/3/131398135/jepare.pdf
    • http://bcpzon4segurabetaviabcp.com/famamefewotuzigam2ll3t.pdf
    • https://cdn.sqhk.co/napumefu/Yejihfc/91433352849.pdf
    • http://tradestaroffice.com/478288578428womo.pdf
    • http://zixaxagewan.mypressonline.com/how_to_connect_bluetooth_on_pioneer_mixtrax.pdf
    • http://autoupgrade.website/lirik_lagu_cant_stop_the_feeling_trollss3rsz.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.opentle.org
    • http://fedorahosted.org/lohit
    • https://s3.amazonaws.com/rodiligarexo/fb_video_iphone_app.pdf
    • https://s3.amazonaws.com/xarojapi/8503709395.pdf
    • https://s3.amazonaws.com/fatisake/81912582762.pdf
    • http://gutekuretejapoj.onlinewebshop.net/adobe_acrobat_editor_full_version.pdf
    • https://s3.amazonaws.com/pafiganovavi/61912785581.pdf
    • https://s3.amazonaws.com/remuv/what_is_health_data_analytics.pdf
    • https://s3.amazonaws.com/nutanigonu/kane_and_abel_book_free.pdf
    • https://s3.amazonaws.com/jepinebawo/5559214446.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/lgpl.htmlRegularDanhHong
    • http://www.geocities.com/dnhhng
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_008_off0001c3d7.bin
ec8fe0305d69899ed399eb20f976486fd8639e66dc7ea077e9aa9e8261128f9e
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1C3D7 19104 bytes
font_00_sfnt_off00014a08.bin
051dc5fe143f6c9acd007ea2e90313426e3aa12d0cc5e1b6455b772e7b0605e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x14A08 5916 bytes
font_01_sfnt_off00015ea2.bin
eec245d535494e4c3848208f48fa54c7dabc2feb05c19fee071aa141c3d1cf18
pdf-font-stream PDF embedded font (sfnt) at offset 0x15EA2 5160 bytes
font_02_sfnt_off00017011.bin
42e9ba47cafc691c79794d811ecf32f2c9e5a0a373a875a65cd1db7ea34fe67c
pdf-font-stream PDF embedded font (sfnt) at offset 0x17011 5700 bytes
font_03_sfnt_off00018168.bin
0b38f6fd5e0b54bfa22d5adee1cfe00629fe134100fc7cfc1ad14a2ab7974207
pdf-font-stream PDF embedded font (sfnt) at offset 0x18168 6148 bytes
font_04_sfnt_off00019148.bin
7b1c2a876b5bf42823f5ad8d9a7288a9736a7213cd58dd9794f456d48ca88e67
pdf-font-stream PDF embedded font (sfnt) at offset 0x19148 16788 bytes
font_06_sfnt_off0001e306.bin
375a32f4b5a630d2093d2c162e5e2a12043542d6d52cecc5c311a82ce68b3ef9
pdf-font-stream PDF embedded font (sfnt) at offset 0x1E306 3248 bytes