Malicious PDF — malware analysis report

Static analysis result for SHA-256 81daf4b07950d8bd…

MALICIOUS

PDF

84.7 KB Created: 2021-03-15 12:01:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0e7e65df179f256b596538d5982175a7 SHA-1: 4ad5d1b47897d94b3665e02f3929c7e286a69d42 SHA-256: 81daf4b07950d8bd876c30484087dedcf1bbc1bc1c1f7c22f00606f3fe3d508f
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, with one prominent URL pointing to 'zajinet.ru', suggesting a link farm or phishing attempt. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, and 'SE_PASSWORD_ARCHIVE_LURE' suggests the document may be a precursor to delivering an encrypted payload. ClamAV also detected this as 'Pdf.Phishing.Trojan'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9957

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=onkyo+tx+sr705+factory+reset
    • https://cdn-cms.f-static.net/uploads/4446273/normal_604499574ed28.pdf
    • https://cdn-cms.f-static.net/uploads/4489264/normal_5fe7bce6e49fa.pdf
    • https://gibodogud.weebly.com/uploads/1/3/5/9/135994226/3382272.pdf
    • https://static.s123-cdn-static.com/uploads/4402720/normal_5ff8b61d64b78.pdf
    • https://pimowaxe.weebly.com/uploads/1/3/5/3/135397576/gebaresubekuke_bisutosulav_tobidiwalelawo_tekigukizu.pdf
    • https://cdn-cms.f-static.net/uploads/4385216/normal_602da4abf3423.pdf
    • https://cdn-cms.f-static.net/uploads/4376358/normal_6026fd7714e41.pdf
    • https://static.s123-cdn-static.com/uploads/4408871/normal_5ff1e7d90851c.pdf
    • https://static.s123-cdn-static.com/uploads/4471252/normal_5fe54f2fc6183.pdf
    • https://cdn-cms.f-static.net/uploads/4444853/normal_5fd107993e39a.pdf
    • https://xabonawof.weebly.com/uploads/1/3/5/9/135965837/wuwabexibuviri_zajuri.pdf
    • https://cdn-cms.f-static.net/uploads/4374022/normal_601db654e5393.pdf
    • https://static.s123-cdn-static.com/uploads/4496818/normal_5ff9ba5912950.pdf
    • https://fobewesepujub.weebly.com/uploads/1/3/2/3/132303403/1135680.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/babuxufarizuxur/apple_magic_mouse_2_space_grey_sale.pdf
    • https://s3.amazonaws.com/nuxomigo/zejiziriraputixu.pdf
    • https://4cd5a77a-be8d-44ba-8952-4177873115c4.filesusr.com/ugd/930050_eb1f206eb28f4ff1ae39e5243f913511.pdf?index=true
    • https://s3.amazonaws.com/kiguteperilodu/somawufofegugafosujobora.pdf
    • https://s3.amazonaws.com/wiwamoxamo/20602409362.pdf
    • https://s3.amazonaws.com/bugutaj/gcc_compiler_optimization_report.pdf
    • https://s3.amazonaws.com/wolawatin/ruxosilobevi.pdf
    • https://3e1af3dc-cf37-4f58-935d-0a6065bc5ce9.filesusr.com/ugd/3ca236_782319dfcced4f4ea1fda744c718414b.pdf?index=true
    • https://s3.amazonaws.com/divexikav/multiplication_worksheets_with_answers.pdf
    • https://s3.amazonaws.com/fedufiporara/aadhar_card_correction_form_filling_example.pdf
    • https://s3.amazonaws.com/nevovumowa/crock_pot_smart_pot_instructions.pdf
    • https://26c1613e-5d28-4fa3-89cb-3d2c9ab59faf.filesusr.com/ugd/fe83c3_a7ab46a322264193861ee89cff098a7d.pdf?index=true
    • https://s3.amazonaws.com/pubopelej/searching_movie_parents_guide.pdf
    • https://45b0b119-5f8c-43e7-b437-4e12d17c1c81.filesusr.com/ugd/3826db_08e6756e369b45dc89268015ca55e631.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010bc1.bin
c88b3f3ee5a67cda3098fe60cf64b00fdba5762f5f1b77f35f8bb1fbbacce660
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BC1 5448 bytes
font_01_sfnt_off00011e79.bin
ed6e5b417eaf3a576f1c1bbe58356ca66bdf2a0f5d7d6509c78aa31303777460
pdf-font-stream PDF embedded font (sfnt) at offset 0x11E79 11228 bytes