Malicious PDF — malware analysis report

Static analysis result for SHA-256 5fe25d38fcaf9118…

MALICIOUS

PDF

76.5 KB Created: 2021-06-10 06:16:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9274725ded940792b58d98b8cd495f77 SHA-1: e97ffda524bac88756032bef77223d3264975794 SHA-256: 5fe25d38fcaf911858b6ab21bbcb0d98ac0c843ffd52c9c1af24622dd1d7bc10
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains heuristics indicating it is a phishing document and has been flagged by a machine learning classifier and ClamAV. The document body, though heavily obfuscated, contains text related to 'Prime video premium apk download', suggesting a lure. The presence of multiple external links, including one pointing to 'synerhu.ru', indicates an attempt to redirect users to malicious content or download sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://synerhu.ru/pbw?utm_term=prime+video+premium+apk+download
    • https://static.s123-cdn-static.com/uploads/4388413/normal_5feb48966dacd.pdf
    • https://bofuvozera.weebly.com/uploads/1/3/5/3/135331850/wegid.pdf
    • https://cdn-cms.f-static.net/uploads/4386335/normal_5fe8bb64b62e3.pdf
    • https://static.s123-cdn-static.com/uploads/4387928/normal_5ffa385870e88.pdf
    • https://cdn-cms.f-static.net/uploads/4379726/normal_60144cd175251.pdf
    • https://wotopegajoxife.weebly.com/uploads/1/3/4/0/134042499/kegimibovut_masalotaz_pipurez_xolavavigafobi.pdf
    • https://kazofinuso.weebly.com/uploads/1/3/4/3/134369681/3099719.pdf
    • https://kedixomavej.weebly.com/uploads/1/3/4/0/134017366/7195153.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/ce8b2cc7-11c2-4537-860b-047dbc9c387d/dell_r710_release_date.pdf
    • https://uploads.strikinglycdn.com/files/00ac5d8c-06ca-4677-9bf3-72f66b9dae56/why_is_my_hard_wired_smoke_detector_beeping_twice.pdf
    • https://uploads.strikinglycdn.com/files/64c3baa3-da54-4058-854c-29dc5f4b678d/vejesakuzazozeselitulup.pdf
    • https://uploads.strikinglycdn.com/files/e47cd904-3712-4c74-a662-877800780a95/koxabawemiposemul.pdf
    • https://uploads.strikinglycdn.com/files/f7408806-114c-4570-a21f-72cd1a94dc6c/how_to_make_mini_militia_hack_version.pdf
    • https://uploads.strikinglycdn.com/files/ad9b970a-ad26-4690-8321-1bd800eb4828/11765474534.pdf
    • https://uploads.strikinglycdn.com/files/c60f3876-82ab-4fc6-81ef-692906858146/understanding_the_books_of_the_bible.pdf
    • https://uploads.strikinglycdn.com/files/c774d2a8-87f3-4a8e-83ce-42daa468835d/54055234040.pdf
    • https://uploads.strikinglycdn.com/files/3011426b-4c76-4333-95de-26ee4913ab66/zekigegafogevunatatezuro.pdf
    • https://uploads.strikinglycdn.com/files/80596bc3-5e28-4aa4-82e6-424749d7eb03/take_a_message_to_garcia_book.pdf
    • https://uploads.strikinglycdn.com/files/5881eb1e-6fbd-4472-9c53-bc2fa30fb458/widigidefimujijinigevo.pdf
    • https://uploads.strikinglycdn.com/files/a0f484ff-f692-42d9-847f-029ffc929571/how_to_invite_guest_to_team_meeting.pdf
    • https://uploads.strikinglycdn.com/files/4bb6b06d-475a-4d86-88dd-5a9376891ed0/63340181332.pdf
    • https://uploads.strikinglycdn.com/files/a474274a-4930-41c4-b7e7-b42472b8236f/bioshock_infinite_modded_save_xbox_360.pdf
    • https://uploads.strikinglycdn.com/files/b58aeab1-46f0-4a2f-938e-0f06cdc27366/zopagudew.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed6a.bin
f3a21c746b1e4ec05cff00a155a3eebc96ddd9b0be9b937d7e5e1b181791e6b4
pdf-font-stream PDF embedded font (sfnt) at offset 0xED6A 5144 bytes
font_01_sfnt_off0000fee9.bin
bfa80f5e953f62f9b5453b91e12ba614de92206c37273558acc5595012593181
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEE9 11180 bytes