Malicious PDF — malware analysis report

Static analysis result for SHA-256 91591d2b978fbc55…

MALICIOUS

PDF

88.4 KB Created: 2021-04-07 23:56:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: b4381bb2f75b2fa4cf2828e510e87f80 SHA-1: 58627e7ee7ac7663ac6102ed733253000bf65f47 SHA-256: 91591d2b978fbc5525673a00e7da699f5ec2d51ca3de61341df7f20a7ce2ba14
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains heuristics indicating it is part of an advance-fee scam, using language related to lotteries, prizes, and courier delivery. It also contains an embedded URI pointing to 'xajibur.ru', which is likely a malicious link used to deliver a payload or redirect the user to a phishing site. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/123?utm_term=audited+balance+sheet+last+date PDF link annotation
    • https://cdn.sqhk.co/vavetiset/jblhaie/used_concrete_cattle_guard_forms.pdfIn PDF document text
    • https://cdn.sqhk.co/remonupode/c6jiXgh/sukurunumivokatan.pdfIn PDF document text
    • https://cdn.sqhk.co/rawavuzom/WSujhgj/cm_rewards_app_apple.pdfIn PDF document text
    • https://cdn.sqhk.co/wabasenenem/bLRz1Xn/63532121236.pdfIn PDF document text
    • https://cdn.sqhk.co/mifijizudi/RicujbG/anz_mobile_digital_wallet.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/zodawanuror/chinarayudu_telugu_movie_free.pdfIn PDF document text
    • https://s3.amazonaws.com/zategafozasiru/bsf._nic._in_online_form_2019.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d3324bc0-f9a7-41ba-8ae8-f3408ce80c7d/what_does_grantee_mean_in_real_estate.pdfIn PDF document text
    • https://s3.amazonaws.com/pisedij/17693708125.pdfIn PDF document text
    • https://e1cd7dcf-8988-4be8-9b1a-722367337987.filesusr.com/ugd/6203b9_b8efa18ce56744dcaf16075ca1f62417.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/7b58642f-9cca-4b17-923f-aff0b7fd1a1f/black_and_decker_lids_off_parts.pdfIn PDF document text
    • https://82656f1f-dd0f-4426-89ca-c5688288f975.filesusr.com/ugd/56de54_9c291cbd554b457abcde5aaba18d43a0.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/nimuwet/segutowafav.pdfIn PDF document text
    • https://89f68ddc-9f98-4e60-8afa-3e0ca6603e9e.filesusr.com/ugd/4725f1_9101686a131f48aa9addc2b283dd7b37.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/dalava/pigimox.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f7210555-d80e-4f82-91ef-8e261bae3800/aladdin_arabian_nights_piano.pdfIn PDF document text
    • https://s3.amazonaws.com/dazuxujepov/latitude_e7450_specifications.pdfIn PDF document text
    • https://s3.amazonaws.com/vibuvomomuv/what_is_the_definition_of_a_random_number_table.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011c3a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11C3A 5060 bytes
SHA-256: 0ff7016325085a5724becf1aec795ab1049489053acdbc0865dc1ebe961f6d96
font_01_sfnt_off00012d67.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12D67 11624 bytes
SHA-256: b4574d082e172454d4af5e2d2b87c73fae5a3cf81f81ad6f00353133bd9b8df1