Malicious PDF — malware analysis report

Static analysis result for SHA-256 6aae34dc561bb4ac…

MALICIOUS

PDF

96.5 KB Created: 2021-04-26 19:00:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 3e566d698efc04f751b06f1466196043 SHA-1: 22d06160c94dfa150433ffbc08c193823c8cb9b7 SHA-256: 6aae34dc561bb4ac19ad4cfdad8ff78b4a5b01e2c2c41ce417aa9f7d1c720bad
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which are obfuscated or lead to potentially malicious domains, as indicated by the 'PDF_SEO_LINK_FARM' and 'ML_NYX_PDF_MALICIOUS' heuristics. The ClamAV detection further confirms its malicious nature, identifying it as 'Pdf.Phishing.Trojan'. The primary malicious URL identified is zajinet.ru, which is likely used to host phishing content or download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=pellon+725+heavy+duty+wonder-under+instructions PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4449392/normal_6001cfc4cf1bb.pdfIn PDF document text
    • https://cdn.sqhk.co/xavipinav/ggO9Orn/tuzakatisi.pdfIn PDF document text
    • https://cdn.sqhk.co/legesizas/jehbAim/mma_vs_wrestling.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393499/normal_600f82823f8f2.pdfIn PDF document text
    • https://cdn.sqhk.co/puvubuzu/oxkgfgh/borderlight_live_wallpaper_free.pdfIn PDF document text
    • https://cdn.sqhk.co/dizoketa/whJirje/89376635872.pdfIn PDF document text
    • https://cdn.sqhk.co/vufisolepu/J2gcnQj/pamifojusone.pdfIn PDF document text
    • https://cdn.sqhk.co/wefenilu/dbqgdhe/53688425739.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4375525/normal_5ffc6393777ca.pdfIn PDF document text
    • https://cdn.sqhk.co/pobopuwubox/Vgd7gev/87224787637.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4443624/normal_5fd7a15454998.pdfIn PDF document text
    • https://cdn.sqhk.co/wigatozaduw/iNQO7MR/tuxatukiwuxefazela.pdfIn PDF document text
    • https://cdn.sqhk.co/raxuzuvuluf/ie6ihgc/sutazajepu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://57e596f1-a2cf-4e3c-9ba9-dc8e42e7d639.filesusr.com/ugd/1e1da7_1c6abcc5e6694f75a2eb69e0ce7409b1.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/saxefi/59347644720.pdfIn PDF document text
    • https://s3.amazonaws.com/muwomapotumugi/dulekuwewuxapi.pdfIn PDF document text
    • https://s3.amazonaws.com/jumedemimo/14816339525.pdfIn PDF document text
    • https://s3.amazonaws.com/bisazabe/37203278393.pdfIn PDF document text
    • https://77a80da1-97a3-4b40-ba11-54c6d232eb66.filesusr.com/ugd/39a0fd_4b6ec4691253480c933034e26a09be9d.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/zidosozawok/how_long_does_russian_volume_lashes_last.pdfIn PDF document text
    • https://8909b315-4d59-4940-aabf-0fdaa532e0ad.filesusr.com/ugd/4542d9_80e7f5db33044d78b9b6d9876fed2cf2.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/zemigiduwagafu/android_nearby_api_tutorial.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011f6c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11F6C 5532 bytes
SHA-256: 93d73b8752859af263ff8f6d981b0307aa92e204248ae6fcf501d940acd68987
font_01_sfnt_off0001324c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1324C 1800 bytes
SHA-256: e9a5a1f6ed95b1e3669933bb00002ad32a1708c3e0b735191cad5e02368a6c7d
font_02_sfnt_off00013ada.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13ADA 12304 bytes
SHA-256: 29103411a63f414093d92cc2e7e0876880d7b176e9ec62a84f8db4f707dfd1e6
font_03_sfnt_off00016401.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16401 4324 bytes
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f