Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e2f7d3bd445b33f…

MALICIOUS

PDF

99.9 KB Created: 2021-06-12 00:13:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6e9ac06cd78eac649c3b62929adb8cf5 SHA-1: 275fc00c9bb793d6dd87cae56df59ddc63098002 SHA-256: 0e2f7d3bd445b33f77c45a0dbeb8099bbef0d8c3ebbc109f7015f41e13490fb6
134 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. The presence of numerous external URIs, including one pointing to 'inwebjor.ru', suggests it's designed to redirect users to potentially harmful content. The heuristic 'PDF_SEO_DISPOSABLE_LINK_FARM' further supports this, indicating a link farm on disposable hosting, often used for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://inwebjor.ru/pbw?utm_term=whatsapp+status+video+happy+birthday
    • https://mitiguranam.weebly.com/uploads/1/3/4/4/134456526/gilewowewi_tusaperur_jimajavar.pdf
    • https://static.s123-cdn-static.com/uploads/4448535/normal_5ff22f43bf6a0.pdf
    • https://xosagosogasimaj.weebly.com/uploads/1/3/1/4/131453054/kilubapitonadanad.pdf
    • https://cdn-cms.f-static.net/uploads/4479715/normal_600b5551ec883.pdf
    • https://levapexufusetij.weebly.com/uploads/1/3/4/9/134904519/parigat_gelawuf_jejenor.pdf
    • https://static.s123-cdn-static.com/uploads/4374188/normal_5fce8b23ae260.pdf
    • https://static.s123-cdn-static.com/uploads/4464068/normal_60074600aa09a.pdf
    • https://sitakubijilu.weebly.com/uploads/1/3/0/7/130776110/897b4665369d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://nikekuva.pbworks.com/f/how_to_put_cover_on_maxi_cosi_pria_85.pdf
    • http://vananizi.pbworks.com/w/file/fetch/144504774/what_ford_vin_numbers_mean.pdf
    • http://pinurakus.pbworks.com/w/file/fetch/144549633/how_to_do_direct_and_indirect_speech.pdf
    • http://zezupagijene.pbworks.com/f/nifuladerojetusunovob.pdf
    • http://jotoxipigi.pbworks.com/f/what_person_does_boxer_represent_in_animal_farm.pdf
    • http://mogulazedub.pbworks.com/w/file/fetch/144523695/how_to_edit_a_bank_statement.pdf
    • http://jotoxipigi.pbworks.com/w/file/fetch/144633801/romeo_juliet_movie_audio_songs_free_download.pdf
    • http://sufasujozu.pbworks.com/f/fox_sports_go_on_roku.pdf
    • http://fotikeralo.pbworks.com/f/coursera_machine_learning_week_3_quiz_answers_regularization.pdf
    • http://lugozamuxika.pbworks.com/w/file/fetch/144564723/kpss_nlisans_trke_deneme_2020.pdf
    • http://pajawazo.pbworks.com/w/file/fetch/145013766/roman_number_of_100_to_200.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9f6.bin
1fe8f6727ca64ebb43d175aae33708643cc84d1c4de43de39eca9e939ec9f27c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9F6 5328 bytes
font_01_sfnt_off0000fc18.bin
6c1c77f22bc50a78eb35261bc873d116208e8dbdf7aa2be76450453f0606fe1f
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC18 13328 bytes
font_02_sfnt_off00012639.bin
e3496c414d45d1e3a7cf5de45d6737554bf03b6f56bba2b97e8aacf21ca0e701
pdf-font-stream PDF embedded font (sfnt) at offset 0x12639 10500 bytes
font_03_sfnt_off00014a7b.bin
91ecf298444dcc572694415c396ea02ed29a771b32cf3e1eb19ee8434407aab4
pdf-font-stream PDF embedded font (sfnt) at offset 0x14A7B 17808 bytes
font_04_sfnt_off000162ea.bin
8dba2135e14a5b554fc2f0fe0010a18261ce2e6bd2cee3faea5ffead84d249c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x162EA 9104 bytes