Malicious PDF — malware analysis report

Static analysis result for SHA-256 53dab331439d84e4…

MALICIOUS

PDF

75.9 KB Created: 2021-05-18 17:00:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1ece2ad83955849899709bfb97497ca7 SHA-1: 75b2f5941dfa1dac80b885a49877099c73c4cafc SHA-256: 53dab331439d84e47b79ccf28a2e41fca1f2341289048961c81ba255a39135a3
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous external links, characteristic of a link farm or SEO spam, with one URL pointing to zajinet.ru. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' suggests the document may be a pretext for delivering a password-protected archive, a common tactic to bypass security scanners. While no scripts were directly extracted, the presence of embedded URIs and the ML classification strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=como+atualizar+o+curr%25C3%25ADculo+na+plataforma+lattes
    • https://besuweleterum.weebly.com/uploads/1/3/2/8/132814030/fazazuwadativuj.pdf
    • https://nodifolosorak.weebly.com/uploads/1/3/4/7/134758422/fazoxobip-ruwiwu-demufodegosukob-mobukiz.pdf
    • https://busuwezaba.weebly.com/uploads/1/3/4/0/134042496/0f0bc7bf4.pdf
    • https://kisinamaku.weebly.com/uploads/1/3/0/8/130814290/769e8bd0f8.pdf
    • https://rijojuno.weebly.com/uploads/1/3/5/3/135310883/50644.pdf
    • https://digexuvin.weebly.com/uploads/1/3/2/8/132814990/banepukurexon_kerumi_mubodag.pdf
    • https://lovapunosarimol.weebly.com/uploads/1/3/5/4/135401421/1776959.pdf
    • https://zakikubefetopu.weebly.com/uploads/1/3/2/6/132696201/zuxaputerufot.pdf
    • https://lepoboniw.weebly.com/uploads/1/3/0/9/130969744/vejajavovodejemaz.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/gidibesuxi/vavifibutimadi.pdf
    • https://s3.amazonaws.com/pubopelej/47126681719.pdf
    • https://s3.amazonaws.com/dobesogum/43855190635.pdf
    • https://s3.amazonaws.com/jivagajamav/best_bootstrap_navbar_templates.pdf
    • https://s3.amazonaws.com/nowokil/glencoe_health_book_chapter_4_assessment_answers.pdf
    • https://s3.amazonaws.com/tojabixefova/spectrum_remote_ur5u-8780l-twm_manual.pdf
    • https://s3.amazonaws.com/tiniruru/boderik.pdf
    • https://s3.amazonaws.com/lanubili/65889520680.pdf
    • https://s3.amazonaws.com/tabobujimo/kevepuwofavetexufivil.pdf
    • https://s3.amazonaws.com/libusamagowuvo/93410889960.pdf
    • https://s3.amazonaws.com/ronenitevodo/54989940335.pdf
    • https://s3.amazonaws.com/tirimofufemukat/72959328384.pdf
    • https://s3.amazonaws.com/pegebunov/types_of_poetry_to_teach_elementary_students.pdf
    • https://s3.amazonaws.com/viwoxuz/gowukibufazabexorolilomin.pdf
    • https://s3.amazonaws.com/tuxalowafokuvo/98439966169.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e6d0.bin
52f5c7db43660e66fe38fcc3ab818d5675eb65cbffcd8c07fcc2cfe7873efb55
pdf-font-stream PDF embedded font (sfnt) at offset 0xE6D0 5168 bytes
font_01_sfnt_off0000f854.bin
63ffe9679486cbb7d8978208579077a37e49d803f1471020aca463ceeb673602
pdf-font-stream PDF embedded font (sfnt) at offset 0xF854 13148 bytes