Malicious PDF — malware analysis report

Static analysis result for SHA-256 92bd1206bfcbb648…

MALICIOUS

PDF

70.7 KB Created: 2021-04-01 07:38:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 28bccfd1778dd9002725b22cff6e42db SHA-1: d99224031874f9933e1a2b1767fd6d92b601634f SHA-256: 92bd1206bfcbb6487d086a4a6a617d14c017c60b3b600e4ee97d011cabbb6d5a
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier. It contains multiple embedded URIs, with https://zajinet.ru/wix?keyword=sas+zombie+assault+td+unblocked being a primary indicator of malicious intent. The PDF also exhibits characteristics of a link farm on disposable hosting, suggesting a phishing or malware distribution campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=sas+zombie+assault+td+unblocked PDF link annotation
    • http://vexoxem.scienceontheweb.net/10th_class_science_notes_rbse_2020.pdfIn PDF document text
    • http://zonuvak.medianewsonline.com/preposition_with_meaning.pdfIn PDF document text
    • http://xepuxupipe.mywebcommunity.org/gonuranolinubunivoramu.pdfIn PDF document text
    • http://figejewumoposes.getenjoyment.net/haloalkanes_class_12.pdfIn PDF document text
    • https://cdn.sqhk.co/kaxopejitin/azJFDhh/abbey_road_zebra_crossing_cam.pdfIn PDF document text
    • https://cdn.sqhk.co/dofofigeniso/mEOhjgd/84780505522.pdfIn PDF document text
    • https://cdn.sqhk.co/nixenexax/h8FhcBF/manevafezesawamosoduj.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://d3df31c7-72fe-42b1-a92e-0723e8ed7a16.filesusr.com/ugd/5bf82b_ebdeaa3aa22e4fa3805bd09f96a60dcc.pdf?index=trueIn PDF document text
    • https://ecf8b3bd-8201-449f-a39c-156acd88681e.filesusr.com/ugd/97634b_c210669fdc9548b0ad8ac775fb53b34e.pdf?index=trueIn PDF document text
    • https://aefbb2f1-1cfc-4a48-aab2-d72547d84173.filesusr.com/ugd/2f3ac6_8957d6bbd0ff4ed6b772987cbb559464.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/9ca12725-3157-4957-97c8-a2297ae6323d/volume_of_compound_shapes_formula.pdfIn PDF document text
    • https://s3.amazonaws.com/tupofelasujewas/62553899207.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4804dc0e-4b9d-4a2e-bce9-88a015fb549a/26112918666.pdfIn PDF document text
    • https://0e733887-fd72-4d21-8b10-0a39cafbc931.filesusr.com/ugd/1e4d10_c91eb86f557746c598faad9fb854f2e9.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/rebomedug/woxit.pdfIn PDF document text
    • http://wufikemofumop.atwebpages.com/how_to_clean_danby_air_conditioner_filter.pdfIn PDF document text
    • https://s3.amazonaws.com/kiguteperilodu/what_does_fresh_off_the_boat_mean.pdfIn PDF document text
    • https://42f4b946-f871-4f2a-a73e-6571c6569919.filesusr.com/ugd/e20521_d91d8454aa7e4e86a80f0a3a6e572d87.pdf?index=trueIn PDF document text
    • https://b70645e9-42d7-44c6-80f2-f165c8819e8d.filesusr.com/ugd/3f1130_343d15f8c80a4e078b0461409ffd9894.pdf?index=trueIn PDF document text
    • https://1e16da7b-5b4f-4122-a3c4-5c88c9d97cf7.filesusr.com/ugd/83f04e_704f5d270ed64101a5e22db0dd4942f0.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/wutisigila/kugepunefobererux.pdfIn PDF document text
    • https://s3.amazonaws.com/lakujusitejojet/71331134123.pdfIn PDF document text
    • https://5efcf519-4c71-4be9-a00f-e1d47ba804c5.filesusr.com/ugd/ebcc4b_143ecbb9508049b790ccb6eef888208d.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d85b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD85B 5344 bytes
SHA-256: 067b3ebd978c5c6792a7ed4faa854cdfa17f1e9ae95536636dc877cef2a90f89
font_01_sfnt_off0000ea7f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEA7F 10200 bytes
SHA-256: 353fd2c7021c9b56338ff9970fb16161fb93b72710d459248a2d9ddd435750c1