Malicious PDF — malware analysis report

Static analysis result for SHA-256 9ed871d117fef831…

MALICIOUS

PDF

86.5 KB Created: 2021-04-28 08:49:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 038e677b75ff445a4c900e2e6da9bdc7 SHA-1: 404a0fdd6fad9667389ee655e66dbbe6eadb58b2 SHA-256: 9ed871d117fef83125e530c46c3f18100f3390782bbf5006858679342bf0ac23
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was detected as malicious by ClamAV and an ML classifier, with high confidence. Heuristics indicate it contains a link farm and an advance-fee scam lure, suggesting the document's purpose is to trick users into visiting malicious links for fraudulent purposes. The primary malicious URL identified is ponafet.ru.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=resumen+del+libro+ficciones+de+jorge+luis+borges
    • http://richteam.site/90336831227hiyc9.pdf
    • http://ledimpress.biz/45182783478hxyri.pdf
    • http://mkuu.club/47863248753uxfap.pdf
    • http://yandex-delivery.cc/what_is_the_less_normal_more_on_instant_pot7ndbf.pdf
    • http://nutristrike-shop.ru/how_to_make_base_in_dayz3vu2m.pdf
    • http://strapslap.online/precalculus_textbook_mcgraw_hill30xfy.pdf
    • http://thelait.pro/college_prep_algebra_2e_workbook_answersdekcw.pdf
    • http://strita.space/wukojudiwfxjeb.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/5688092c-fc1a-4890-854f-e6262ca57632/rutugariwozekezaw.pdf
    • http://nizalag.rf.gd/email_id_validation_regular_expression_in_android.pdf
    • http://kixeret.rf.gd/bdlaws_gov_bd_part.pdf
    • http://molagisonapem.epizy.com/24609079993.pdf
    • https://uploads.strikinglycdn.com/files/96395be9-0e90-40e4-8c39-a2f1f0d0f5da/mijuvevelevodonerotu.pdf
    • https://1ffb5d6c-d890-49e0-9b87-dc10fbfa49e2.filesusr.com/ugd/8bc2a6_58b2c5596e494eb4a154d645ddfc35a6.pdf?index=true
    • https://uploads.strikinglycdn.com/files/c5502c24-ff1d-48bd-b456-18fb85f83730/77719653715.pdf
    • http://bilumolekotejoj.rf.gd/mortal_instruments_casting_director.pdf
    • https://6cbe2f5c-748b-4bc6-b691-25a968a47885.filesusr.com/ugd/d6b5da_aea6f5d457234914ace6f9e4447a0fc5.pdf?index=true
    • https://uploads.strikinglycdn.com/files/abcd19c0-0080-486b-8bbc-903bb7890216/dijekeminag.pdf
    • https://uploads.strikinglycdn.com/files/d2341d32-5243-4b1a-b981-7070c0f17364/into_the_woods_script_musical.pdf
    • https://uploads.strikinglycdn.com/files/c842871e-1f88-4805-a6e7-7c7dfba61774/roguxawonubavofok.pdf
    • https://uploads.strikinglycdn.com/files/1fab2626-bd19-40a8-af7d-5d1abcba68c0/80107057927.pdf
    • https://uploads.strikinglycdn.com/files/383fc393-bb25-4135-b2d2-046c26d01eca/70885645238.pdf
    • http://zidumive.rf.gd/26925304517.pdf
    • https://uploads.strikinglycdn.com/files/18f4ec0b-34ac-4970-8469-69980f4dfcb4/95285449608.pdf
    • https://9170d309-caca-4186-8987-bf6b40ce219c.filesusr.com/ugd/baef12_ccc7580f5a454cff869c106b6baffb57.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011311.bin
3059810c201c673b51e5c2651db53c446823db30fc430caeb4ccc81b6e9dc695
pdf-font-stream PDF embedded font (sfnt) at offset 0x11311 5356 bytes
font_01_sfnt_off0001253a.bin
d99c4128e1fd0a34a48e2a62845d606fca95b4fcc19e0cdfd80fc0a96ad7ec66
pdf-font-stream PDF embedded font (sfnt) at offset 0x1253A 11956 bytes