Malicious PDF — malware analysis report

Static analysis result for SHA-256 334a9372affa442e…

MALICIOUS

PDF

79.3 KB Created: 2021-03-24 23:45:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b47be7e99019ebc5f533231aadf4b88f SHA-1: 3b965476c7ba28d97679431368ba55273590dcd5 SHA-256: 334a9372affa442ee6038ec0cf795d5522fe4a4abf4f163e49e038da836505b7
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF file contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic, pointing to various domains. One of the primary external URIs, 'https://zajinet.ru/strik?utm_term=dyson+v11+animal+cordless+vacuum+cleaner+%2526+bonus+accessories', suggests a lure related to product searches. The ClamAV detection and ML classifier strongly indicate maliciousness, likely related to phishing or malware delivery through these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=dyson+v11+animal+cordless+vacuum+cleaner+%2526+bonus+accessories
    • http://gagimubu.mywebcommunity.org/alexa_commands_in_spanish.pdf
    • http://bevamifugidujew.scienceontheweb.net/azan_ke_baad_ki_dua.pdf
    • http://logunej.iblogger.org/information_asymmetry_in_agriculture.pdf
    • http://lelekelosutov.getenjoyment.net/kovofiwikozegogokozuwa.pdf
    • http://rigojakivuvemi.iblogger.org/47627676499.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/0bfb3587-9ec5-4d18-a756-9cdadd1d853a/what_milestones_should_a_3_month_old_have.pdf
    • https://s3.amazonaws.com/kisagoz/2296073830.pdf
    • https://c02a3fa2-970f-4384-b4fa-7a60184a1b73.filesusr.com/ugd/1da3fe_45cf87882b17433eab26b4608c467d0d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a6cfdb35-35cd-4966-8909-c619baaef3ba/vajulexamufolina.pdf
    • https://s3.amazonaws.com/poguvelefa/fifty_shades_freed_full_movie_download_dual_audio_480p.pdf
    • https://uploads.strikinglycdn.com/files/ea18166d-a632-433c-93cb-3c5adcfd2d39/47759181553.pdf
    • https://uploads.strikinglycdn.com/files/8ab53fd4-b2c8-45da-9df4-d3380f75006f/how_do_i_pair_my_afterglow_headset.pdf
    • https://165abacb-5525-4e66-971c-c167d859e756.filesusr.com/ugd/f3f2a5_dda3c157cc10499e9883023884c33556.pdf?index=true
    • http://tebuwawezizafes.onlinewebshop.net/they_say_i_say_free_online_book.pdf
    • https://uploads.strikinglycdn.com/files/dca6dae7-8ab1-4973-92e1-6b62d0c944e3/where_to_watch_the_draft_lottery.pdf
    • https://s3.amazonaws.com/xumakomowi/movixeb.pdf
    • https://uploads.strikinglycdn.com/files/4bed13ff-0a9c-4fcb-a433-07a32eb945b0/hp_probook_4530s_bluetooth_drivers_for_windows_7_64_bit.pdf
    • http://sugudilun.epizy.com/reality_capture_crack_free.pdf
    • https://0502d5d0-a0f5-47b8-bc1c-644c46e4e431.filesusr.com/ugd/6cabbb_76621f7c411b437f92a4fd22c44ca601.pdf?index=true
    • https://uploads.strikinglycdn.com/files/52842283-5ef8-499e-be73-5501bf47f7e9/denow.pdf
    • https://uploads.strikinglycdn.com/files/910e24f2-45be-4bf5-a62b-536b0c06f003/modetoreroji.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f7ff.bin
7878ffbc12260d46154e367e30e59b0a541a74516b6eeaffdea37ec724fcbcdc
pdf-font-stream PDF embedded font (sfnt) at offset 0xF7FF 5300 bytes
font_01_sfnt_off00010a06.bin
fd6b281cec1b4136631b94ee8e083f9e96f377320598e1ee278ead73e793a82c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A06 11076 bytes