Malicious PDF — malware analysis report

Static analysis result for SHA-256 20fa3f7f960cd393…

MALICIOUS

PDF

129.2 KB Created: 2021-03-22 01:30:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ec09fdfd02a16143ba3a186cdd9e9314 SHA-1: 2b690be73a5119656a8388d07271b632857f1a57 SHA-256: 20fa3f7f960cd393f985571255f772151f61d12ced86ff7c74452400f94863b0
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic identifying it as a 'PDF_SEO_LINK_FARM'. The primary external URI points to 'https://jacksth.ru/wix?keyword=%25D8%25B1%25D8%25B3%25DB%258C%25D9%2588%25D8%25B1+%25D9%2585%25D8%25AF%25DB%258C%25D8%25A7+%25D8%25A7%25D8%25B3%25D8%25AA%25D8%25A7%25D8%25B1+1800', suggesting a lure or redirection mechanism. ClamAV also detected this as 'Pdf.Phishing.Trojan'. While no scripts were explicitly extracted, the structure and heuristics strongly indicate malicious intent, likely related to phishing or distributing further malicious content via the linked PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9948

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=%25D8%25B1%25D8%25B3%25DB%258C%25D9%2588%25D8%25B1+%25D9%2585%25D8%25AF%25DB%258C%25D8%25A7+%25D8%25A7%25D8%25B3%25D8%25AA%25D8%25A7%25D8%25B1+1800
    • http://samyog.ru/wipijg4tn9.pdf
    • http://supermagazforsale1.xyz/90858722862jwih5.pdf
    • https://static.s123-cdn-static.com/uploads/4405930/normal_6002ee5971830.pdf
    • https://cdn-cms.f-static.net/uploads/4387036/normal_601fcd400d56a.pdf
    • http://lnstagramcopyrigtservice.com/17187105616rwx6h.pdf
    • http://prodive.su/96771706434nmh4j.pdf
    • https://rujibuteza.weebly.com/uploads/1/3/5/3/135308743/1662713.pdf
    • https://teguzefememefa.weebly.com/uploads/1/3/4/6/134609716/79930d3a4cd41.pdf
    • https://meronikam.weebly.com/uploads/1/3/4/7/134705372/3806ccdc2.pdf
    • https://cdn-cms.f-static.net/uploads/4410730/normal_6021bf2fb7384.pdf
    • https://mizemajawoxulu.weebly.com/uploads/1/3/1/4/131437858/3234220.pdf
    • https://cdn-cms.f-static.net/uploads/4453579/normal_5fe91ce9bcd28.pdf
    • http://m-ryanaf.site/11935374032yqobv.pdf
    • https://cdn-cms.f-static.net/uploads/4480891/normal_60283d934c0cf.pdf
    • https://bojewozawix.weebly.com/uploads/1/3/4/3/134321988/pelizetotimogoru.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://dutuxiratuno.rf.gd/agatha_christie_books_age_range.pdf
    • http://baruneridetaju.epizy.com/beveveven.pdf
    • https://uploads.strikinglycdn.com/files/a83f7a0b-b93c-4357-94c2-8fb03bda431b/the_primary_disadvantage_of_contiguous_storage_is_that.pdf
    • http://fipotunisobojow.epizy.com/nefolanutij.pdf
    • https://uploads.strikinglycdn.com/files/563f52b6-b6e6-4ad5-ba7c-5a273634bd18/86665904919.pdf
    • https://uploads.strikinglycdn.com/files/a4f0d56a-96be-4335-a59e-2694b372ad49/texas_instruments_ba_ii_plus_manual_reset.pdf
    • https://uploads.strikinglycdn.com/files/3b971512-666a-40b4-b502-a9543a9aa6bf/9752144959.pdf
    • https://uploads.strikinglycdn.com/files/4ed001e0-6e10-4933-ae5e-a950de0342f3/free_printable_blank_hundreds_chart.pdf
    • https://uploads.strikinglycdn.com/files/e42cf4f7-424c-4e4c-897b-f5a6b2537b03/69412508350.pdf
    • https://uploads.strikinglycdn.com/files/188c451f-c82d-4b58-afbd-4744a5e639e0/zero_limits_joe_vitale_italiano_free_download.pdf
    • https://uploads.strikinglycdn.com/files/a5ea4c8a-bb84-4bdf-b596-d38f0fe11a48/how_to_fix_svc_tire_monitor_2008_chevy_cobalt.pdf
    • https://uploads.strikinglycdn.com/files/d524b9d3-dc0e-4ee8-bddf-2f730a226bc1/28168542018.pdf
    • https://uploads.strikinglycdn.com/files/43370741-d1f7-4065-94bc-704154d5363b/86018610267.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0001bad8.bin
8254ede504f3185479cea290122d2c25fe7f7a0e84ff5504d7e072e4a958c2ab
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1BAD8 31892 bytes
font_00_sfnt_off00017091.bin
456aeb7fc4afa54304c831dfce11c3046cdd11ddc292a34772d9f0176bd2278a
pdf-font-stream PDF embedded font (sfnt) at offset 0x17091 4456 bytes
font_01_sfnt_off00017fd2.bin
24ded6287a525a1f7f07943eec460d28ef28e35213997b1eeac91a50b7d1aa97
pdf-font-stream PDF embedded font (sfnt) at offset 0x17FD2 9944 bytes
font_02_sfnt_off0001a23c.bin
51ebd0a516f133047855c0137ac73137405cfee6c25249e6a6afc927744d61e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A23C 17088 bytes