Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e54c554c2ed92f0…

MALICIOUS

PDF

99.4 KB Created: 2021-03-18 09:59:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9ff1e897c7d939e9fec0e5e8a7dab191 SHA-1: 79c770894bc676ffb29548238de072e9b5a78905 SHA-256: 1e54c554c2ed92f0f88dc2bcf3fc57d4acb9d24e250ecb596c3aa05368d5c24d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with one heuristic specifically identifying a 'PDF link farm' designed for SEO manipulation. The primary malicious URL, 'https://botokaw.ru/strik?utm_term=patch+league+of+legends+10.16', suggests a lure related to a game patch, likely to deceive users into visiting a malicious site. While no scripts were explicitly extracted, the PDF structure and the presence of many external links indicate a malicious intent to redirect users, potentially for phishing or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=patch+league+of+legends+10.16
    • https://cdn.sqhk.co/koletexun/2ohJgcB/85516926050.pdf
    • https://gidiwukos.weebly.com/uploads/1/3/1/3/131381706/tegifivofene.pdf
    • https://jepunitapo.weebly.com/uploads/1/3/1/0/131070437/jipigowogowis_rixamuza_wedurijazemisi_davuneximadipe.pdf
    • https://cdn.sqhk.co/feziwetesene/bIifjgA/speak_english_with_vanessa.pdf
    • https://xaxiduxaze.weebly.com/uploads/1/3/5/3/135308656/1542876.pdf
    • https://cdn.sqhk.co/vopupevomate/2jjFchh/origami_box_instructions.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vuterijoze/animals_survive_without_aircraft.pdf
    • https://9a60fab3-6fb0-4be7-9305-b2e3cc44d963.filesusr.com/ugd/811c4f_f1b8b443233c482aa7e157b54e4fe9f6.pdf?index=true
    • https://ae0ecf71-49bb-4ac4-bba4-d0f2a20d1af9.filesusr.com/ugd/668a47_2ce7a65dc7234a23a3e1d4c38f9e35a9.pdf?index=true
    • https://ee6bc897-aa08-459d-b6e6-b1b1d69fcba1.filesusr.com/ugd/7ba596_2de0e49698774f34b11b76789ac7970c.pdf?index=true
    • https://972af30b-04c2-4618-b911-83ba0b7fef9e.filesusr.com/ugd/84a5c6_7e9f0f7ac41e4bac8a5f49245406e159.pdf?index=true
    • https://s3.amazonaws.com/zikeko/dijamofanusava.pdf
    • https://aefbb2f1-1cfc-4a48-aab2-d72547d84173.filesusr.com/ugd/2f3ac6_6c38e1d17d8e4dbe8dd2c60a1e8e4b6b.pdf?index=true
    • https://b998fa74-583e-446a-a2a7-67f41460fdb2.filesusr.com/ugd/e081f8_18860953404c41d59c757c1c12681ff1.pdf?index=true
    • https://441768bb-9839-4df4-8f78-dd1233b527f6.filesusr.com/ugd/7e6080_976b53c2bc1440febc0fbf0970ddd89c.pdf?index=true
    • https://3a00e800-a8eb-44ae-aafc-ae9aecab8e06.filesusr.com/ugd/1715bf_b3ae0dd886bf45c6a504a44f5b407885.pdf?index=true
    • https://1a441fb4-51dd-4528-a053-eb59ff664e18.filesusr.com/ugd/43d9d5_17e0a14e2d6f4ba09c1f8685079dd857.pdf?index=true
    • https://s3.amazonaws.com/dotivaf/wordscapes_answers_1041.pdf
    • https://234d5d8d-19c9-4cab-a884-dd0775662658.filesusr.com/ugd/fb7225_e08f18a88af94c44b2611ba5bd0bc2ce.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012ef1.bin
00d2eb90d65a050e5e4f333829758a265a9884fc7efcbad12a315702d2b70547
pdf-font-stream PDF embedded font (sfnt) at offset 0x12EF1 5568 bytes
font_01_sfnt_off000141ec.bin
538f3def2f6417500a5826e94b949a442d3cffdc1d08e65b4ffdecb3d2611415
pdf-font-stream PDF embedded font (sfnt) at offset 0x141EC 11920 bytes
font_02_sfnt_off0001698e.bin
3a87a2a80cb0740ff7ad33dbd9b35031d90241dfccc5ab96a3d2c3133af9c3ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x1698E 16096 bytes