Malicious PDF — malware analysis report

Static analysis result for SHA-256 891d03cf7b42e0a2…

MALICIOUS

PDF

95.3 KB Created: 2021-03-24 12:09:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a03f0787047d78f67225c5e4ff06be00 SHA-1: 77ab94b2751356a17d27fcc36674543bcbba7355 SHA-256: 891d03cf7b42e0a23b4bf4ef26fa2a17c7ecd55a31b09e2478ed8064b44d96d8
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a common tactic for SEO spam and phishing. The heuristic PDF_SEO_LINK_FARM indicates a large number of links, with one pointing to zajinet.ru. ClamAV also detected this as Pdf.Phishing.Trojan. The presence of embedded URLs and the overall structure suggest an attempt to redirect users to malicious or spam content, likely for phishing or to distribute further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=internet+booster+apk+mod
    • https://zademufexek.weebly.com/uploads/1/3/4/7/134765537/zirifijemijokaxalal.pdf
    • http://graatorama.space/219857826394k1uo.pdf
    • http://bestpriceforukraine.xyz/59622691000j7iiz.pdf
    • http://c-advance.space/tamil_cut_songs_sms_ringtonesi9cp7.pdf
    • https://pegiromilu.weebly.com/uploads/1/3/4/6/134683304/5657031.pdf
    • http://sysfix.ru/26589030770fedom.pdf
    • https://filuwanukolo.weebly.com/uploads/1/3/4/8/134874182/07764e57c2a0155.pdf
    • http://goloturasituj.66ghz.com/94841753366.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/63f2c465-d7cc-49e5-a310-452775fd0497/38715080997.pdf
    • https://uploads.strikinglycdn.com/files/3e3e8ddf-5b3c-456d-84da-abff31de6bc0/42422858542.pdf
    • https://s3.amazonaws.com/nademopor/suzewizubojikikavaziwoz.pdf
    • https://uploads.strikinglycdn.com/files/6fe3c439-7af3-4d92-bfb1-5612beec6c8f/sifuso.pdf
    • https://uploads.strikinglycdn.com/files/9156e42a-df4d-47a7-940a-e11ad27c51da/jack_lalanne_power_juicer_express_manual.pdf
    • https://s3.amazonaws.com/mokuwanibof/97888084245.pdf
    • https://uploads.strikinglycdn.com/files/b7836e92-3601-4aaf-abd8-965e45bdad3c/67024365595.pdf
    • http://jawomutiz.epizy.com/wikefuxomuworodogifu.pdf
    • https://uploads.strikinglycdn.com/files/b0f49b04-f6db-49ab-9b02-1c20b0a9e111/how_to_turn_on_kitchenaid_induction_stove_top.pdf
    • http://lofadezowudekeg.epizy.com/99030985668.pdf
    • https://uploads.strikinglycdn.com/files/03a06af2-0b1c-4b44-a16f-6d02dd50164a/8972012704.pdf
    • https://uploads.strikinglycdn.com/files/28a6fc9d-3f56-47e2-a493-0e98323cc367/how_to_use_the_hoover_spinscrub_50.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0001510e.bin
9d9e3c04ac4e9de9a24619a0fd16101053548e019951a40a03cd88cb7543722c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1510E 18928 bytes
font_00_sfnt_off00011800.bin
3b20ae7502af397ce22d306e6f6aaa58835a18ced6320c21e454d1043f8abf8c
pdf-font-stream PDF embedded font (sfnt) at offset 0x11800 5216 bytes
font_01_sfnt_off0001299e.bin
1b8edcbfd30852b14506ecc61826c442aae0f35ab58542b2a5db09a900615b14
pdf-font-stream PDF embedded font (sfnt) at offset 0x1299E 11864 bytes