Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e7e72c27c791bf9…

MALICIOUS

PDF

78.4 KB Created: 2021-04-07 05:04:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 397553662b44df1a48029698c5656323 SHA-1: b9b34f130e621f40d4750756d49f58422914d659 SHA-256: 1e7e72c27c791bf9978262ec6ed1fa7f802752fb9bd60ccccdda1b1cf1839205
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains multiple heuristics indicating malicious intent, including PDF_SEO_LINK_FARM and ML_NYX_PDF_MALICIOUS. The embedded URL 'https://botokaw.ru/wix?keyword=go+to+psvue.com%252Factivateroku' is a primary indicator of a phishing or malware distribution attempt. While no scripts were explicitly extracted, the PDF structure and URL farm suggest it's designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=go+to+psvue.com%252Factivateroku
    • https://cdn-cms.f-static.net/uploads/4466140/normal_5fe8815ab8c82.pdf
    • https://cdn-cms.f-static.net/uploads/4417030/normal_6041238c4fb5f.pdf
    • https://cdn-cms.f-static.net/uploads/4485313/normal_605634da40b32.pdf
    • http://rufamegepijuwo.22web.org/grievance_handling_procedure_in_zimbabwe.pdf
    • https://static.s123-cdn-static.com/uploads/4403938/normal_5fe31bfba9599.pdf
    • https://cdn-cms.f-static.net/uploads/4467325/normal_6022debef3dda.pdf
    • http://zepebuporume.iblogger.org/57853987530.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/rodakarugupoko/divefarobo.pdf
    • https://uploads.strikinglycdn.com/files/bb71a347-e43e-46ea-bd64-2b909c7e8711/national_primary_and_secondary_drinking_water_regulations.pdf
    • https://uploads.strikinglycdn.com/files/21e27e0d-5be0-4930-9362-051fef56ef5f/what_is_the_most_common_chord_progression_in_jazz.pdf
    • https://s3.amazonaws.com/luropiw/terraria_android_full.pdf
    • https://s3.amazonaws.com/megodipewukitoj/astro_tv_guide_malaysia.pdf
    • http://nitukerisoz.rf.gd/exercicio_de_atomistica.pdf
    • https://s3.amazonaws.com/lixisariwulo/pafuzul.pdf
    • https://s3.amazonaws.com/zidenigad/16302120788.pdf
    • https://fff5164c-1337-4dca-a870-9ee8129e9d1f.filesusr.com/ugd/11cbe4_2b1c5c9a813b4738be7ff14a0eedeaa9.pdf?index=true
    • https://ce099f17-eb12-430b-a452-8d789b3ee5a8.filesusr.com/ugd/aef5b7_f16155dcfe6b45adaa27407dfaaf25a0.pdf?index=true
    • https://db7841a4-af10-4990-a2be-f084cd4acbf6.filesusr.com/ugd/e3c460_1d2485f28dc4439fa0be4c8e313d3d29.pdf?index=true
    • https://s3.amazonaws.com/veledabejufi/halloween_emoji_pictionary_quiz_answers.pdf
    • https://s3.amazonaws.com/muvemasoxaji/zijodurixifagililomujo.pdf
    • https://s3.amazonaws.com/venunamazozuzo/palelo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f40b.bin
6a21e14328682cc4f8b5d7c9457349bfb0d03960f1532d23080050de4699650d
pdf-font-stream PDF embedded font (sfnt) at offset 0xF40B 5272 bytes
font_01_sfnt_off00010600.bin
e8eeefd121e9edf67fafb88aa68650ee2fec91b39a6033fefdc0eef514533476
pdf-font-stream PDF embedded font (sfnt) at offset 0x10600 11260 bytes