Malicious PDF — malware analysis report

Static analysis result for SHA-256 86009b24bf1c9c4b…

MALICIOUS

PDF

80.1 KB Created: 2021-03-23 07:35:06 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6945de182ed437cef0df8570e10d426b SHA-1: 2c2797fcd351d0c8cd13da458ccceb1f6fdab92d SHA-256: 86009b24bf1c9c4b607a18de66427a6bafb1147deb6bd7af6a35c3d876b9f55c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a critical heuristic identifying a link farm. The primary external URI points to a suspicious domain, 'xezojetit.ru', which is likely used for phishing or to host malicious content. Although no scripts were explicitly extracted, the PDF structure and the presence of many external links suggest an attempt to redirect the user to a malicious site, aligning with spearphishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=positive+action+bible+curriculum+4th+grade
    • https://cdn.sqhk.co/vefusujix/MgdifGU/magic_dragon_village_cheat_apk_download.pdf
    • https://pegepujime.weebly.com/uploads/1/3/1/4/131453637/78f04dacebc80a.pdf
    • https://cdn.sqhk.co/gidagolusi/hgGjgVA/15987792890.pdf
    • http://jogemijafiw.22web.org/levuvamixokototuvu.pdf
    • https://cdn.sqhk.co/suxujaba/hChhhch/caption_programs_definition.pdf
    • http://jepenufi.getenjoyment.net/al_quran_digital.pdf
    • https://cdn.sqhk.co/pulununese/bWFF099/mars_minerals_pelletizing.pdf
    • http://xukejufivakege.iblogger.org/aqualink_rs6_service_mode_is_active.pdf
    • https://vawudida.weebly.com/uploads/1/3/4/8/134890241/2039646.pdf
    • http://lapiwudoxavov.scienceontheweb.net/48590074852.pdf
    • https://cdn.sqhk.co/netimupoxojo/hkheegC/10128794290.pdf
    • https://cdn.sqhk.co/kenalutaxi/hgghuhi/nuvixerewanuruzaluzuzoj.pdf
    • http://nutusugeralinet.mypressonline.com/the_fantastic_four_full_movie_in_hindi_dubbed_download.pdf
    • https://cdn.sqhk.co/zezetemirag/ibigje2/shotgun_firing_sound_effect.pdf
    • https://cdn.sqhk.co/tovipovo/eDuJjfi/idle_prison_empire_apk_mod.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://gotulitedovolen.rf.gd/26900286717.pdf
    • https://uploads.strikinglycdn.com/files/e443b149-ad95-4b3a-b0f7-b48cf987a906/inferno_di_dante_gole_dellalcantara_2020.pdf
    • https://uploads.strikinglycdn.com/files/cff63ba1-5fdc-42d9-8eb4-2f27eb13a296/22404244739.pdf
    • http://vilepobafomunow.atwebpages.com/2d_and_3d_shapes_worksheets_for_grade_1.pdf
    • https://uploads.strikinglycdn.com/files/ce5c4a91-3acf-4f45-b9bf-3b73c70be7a7/written_in_my_own_hearts_blood.pdf
    • http://savefativiluz.epizy.com/nadra_b_form_online.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee06.bin
d2097e3adf03f7d21c2176bf7a30903d5e4b128873b6b3a9f6c89d82cbe99143
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE06 5524 bytes
font_01_sfnt_off000100a3.bin
2f91b049e3667390697261a93590e2bbf9d088c40e7b1093ccf21eae76c8aa17
pdf-font-stream PDF embedded font (sfnt) at offset 0x100A3 10576 bytes
font_02_sfnt_off0001249d.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x1249D 4324 bytes