Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c737efa5ace85cb…

MALICIOUS

PDF

80.3 KB Created: 2021-03-27 09:41:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4246c452c49df85a749e87503f85b89f SHA-1: 7caaeaeecb30eb2d8c95310bc23cfce0a7d54725 SHA-256: 5c737efa5ace85cb917dcb11fec6ae77bdd00143ca1bf01482b5b17048be82e5
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a critical heuristic firing for a 'PDF_SEO_LINK_FARM' indicating a mass of external links. One of the primary URLs, 'https://xezojetit.ru/strik?utm_term=what+is+the+alternative+to+apple+time+capsule', suggests a lure related to Apple Time Capsule alternatives. The presence of XFA forms and a high ML score further support malicious intent, likely for phishing or distributing further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=what+is+the+alternative+to+apple+time+capsule
    • http://copyrightshelpcenter.com/fomugemx5tv4.pdf
    • https://gixefizavemo.weebly.com/uploads/1/3/4/1/134108956/2189382.pdf
    • http://pravagims.net/vekobozokipunuzibesogiljxya.pdf
    • http://zebarugusi.22web.org/reformation_heritage_kjv_study_bible_online.pdf
    • http://goproonly.com/566249209102g4vd.pdf
    • https://bosamekuxukis.weebly.com/uploads/1/3/4/6/134672370/3567278.pdf
    • http://helplnstagramoffice.com/hardware_id_acpi_smo8800gbge8.pdf
    • http://servisvds.ru/the_heart_of_darkness_by_joseph_conradhz8tc.pdf
    • http://trydouche.xyz/21994171838ejlx8.pdf
    • http://namsinc.info/miniature_german_shepherd_puppies_uk6qoco.pdf
    • http://logusubunovad.22web.org/adverbs_worksheet_7th_grade.pdf
    • https://lobobofu.weebly.com/uploads/1/3/4/6/134680821/devefexe-gapibosudi-binage-gidebetuxexew.pdf
    • http://instahelpforbusiness.com/consider_the_frame_shown_in_figurejrxoh.pdf
    • http://sefobadivura.iblogger.org/13063921450.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/5036df41-9bcb-434e-84de-934c206b2a48/cut_patricia_mccormick_genre.pdf
    • https://uploads.strikinglycdn.com/files/1c64f975-21e7-4c5c-95f5-7d23314d72fd/maytag_bravos_xl_washing_machine_reviews.pdf
    • https://uploads.strikinglycdn.com/files/f51cc85b-1356-496f-978f-497f51de2c3b/intent_to_claim_disability_support_pension.pdf
    • https://uploads.strikinglycdn.com/files/b62ddc60-65cc-4468-8d82-ba9646b91c35/zixiwizafizize.pdf
    • http://difugarulid.epizy.com/petikik.pdf
    • https://uploads.strikinglycdn.com/files/774dea79-15cd-4fa8-8332-3ded6e8cd645/hp_p1606dn_factory_reset.pdf
    • https://uploads.strikinglycdn.com/files/d8543f1a-51be-44c7-899f-91145cc7fbcb/ends_based_ethics.pdf
    • https://uploads.strikinglycdn.com/files/7b6722a2-47e5-44ab-a54a-8a77ce391ea6/sininoganaxuji.pdf
    • https://uploads.strikinglycdn.com/files/50328874-9779-4462-bf8e-77e92ca941e3/pavilixuwe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fc26.bin
cef1bc24ac086ec0f9cca94d9725b5091dcc62269cdba1f9864bb1a6bad0f58e
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC26 5244 bytes
font_01_sfnt_off00010de1.bin
0f5c82e69a9397971e20f8ae634f8851897435eb085e68ef4d32a8a3a3f980a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x10DE1 10948 bytes