Malicious PDF — malware analysis report

Static analysis result for SHA-256 114ebdf77c277289…

MALICIOUS

PDF

68.2 KB Created: 2021-02-15 06:46:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f63a94b520d8dc876c09d12c74b87718 SHA-1: 780aa97c3043d1f3d3920f7706aae5bc03d2c4e5 SHA-256: 114ebdf77c27728905e600ffdc9d9ae51ffc24efba6a256c2321e8c4db522e22
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, including one pointing to 'jottigo.ru' with a query parameter suggesting a search result lure, and another to 'sberbank.link' which is likely part of a phishing campaign. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as a phishing trojan. No scripts were extracted, but the presence of embedded links and the nature of the heuristics suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/aws?utm_term=ssms+format+sql+add+in
    • http://sberbank.link/60816122187d0tjf.pdf
    • https://static.s123-cdn-static.com/uploads/4368506/normal_5ffc7f45ceb3e.pdf
    • https://cdn-cms.f-static.net/uploads/4382631/normal_5fd26fc137d22.pdf
    • https://faxezufag.weebly.com/uploads/1/3/0/8/130874059/8921382.pdf
    • https://funavekun.weebly.com/uploads/1/3/0/9/130969801/af8434fe4d699.pdf
    • https://static.s123-cdn-static.com/uploads/4489717/normal_600503098e8d5.pdf
    • http://yewes.space/fakegisewasivukobikanogs8j7.pdf
    • http://24goodstore.site/wobaloxadejere6imv.pdf
    • https://sesemuxedewa.weebly.com/uploads/1/3/4/0/134017121/c399247.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/damerirazib/boney_m_christmas_songs_lyrics_free.pdf
    • https://s3.amazonaws.com/gozifep/clasificacion_de_empresa_segun_forma_juridica.pdf
    • https://s3.amazonaws.com/mesotodimus/xonapugu.pdf
    • https://s3.amazonaws.com/kigavanus/bharathiar_university_mba_syllabus_2017.pdf
    • https://s3.amazonaws.com/muwemivumazulax/aisi_laagi_lagan_song_javed_ali.pdf
    • https://s3.amazonaws.com/sojebelevenex/comparisons_exercises_intermediate.pdf
    • https://s3.amazonaws.com/zoromexemuzid/pisarofawap.pdf
    • https://s3.amazonaws.com/tinivukedeta/sample_investigation_report_employee_theft.pdf
    • https://s3.amazonaws.com/nuxulikiwab/55909878360.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d02c.bin
31ef76a1d1a01a4f9a85df07b83d845eecd04b428876a4cdd22e4bbdd57342ff
pdf-font-stream PDF embedded font (sfnt) at offset 0xD02C 5284 bytes
font_01_sfnt_off0000e204.bin
479ffd9af2e5f3b2bdfac247a4ac1eaa70980087ebe04e4f5edf0022dcad37cd
pdf-font-stream PDF embedded font (sfnt) at offset 0xE204 10016 bytes