Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f12afbab50aa1e1…

MALICIOUS

PDF

74.7 KB Created: 2021-03-31 00:51:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4180fdeef268690488e78ab0befc331d SHA-1: bde5d56735ea01ce811a885a716bed509ab00b1e SHA-256: 9f12afbab50aa1e15b9193b2218b47a66eab9b07ae106c7cc9bfce7c5a9e1ccf
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for SEO poisoning or phishing. The heuristic 'SE_ADVANCE_FEE_SCAM_LURE' strongly suggests the document's content is designed to trick users into believing they are involved in a lottery, prize, or parcel delivery scam, aiming to extract money or information. The presence of embedded JavaScript, though not directly analyzed for specific malicious actions, is often used in PDFs to facilitate malicious redirects or exploit vulnerabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/strik?utm_term=is+current+stock+market+a+bubble
    • https://cdn.sqhk.co/sofetarunox/dehjMgh/telegram_and_gazette_classified_apartments.pdf
    • https://cdn.sqhk.co/vesagivara/FieAwjf/sample_business_plan_for_investors.pdf
    • https://xapefawisago.weebly.com/uploads/1/3/4/7/134771693/216543.pdf
    • https://cdn.sqhk.co/vabalogu/eSzhchf/two_dots_travelers_trail_level_4.pdf
    • https://cdn.sqhk.co/xovepejegosi/ajbMgff/final_freeway_2r_apk_pure_app.pdf
    • https://cdn.sqhk.co/zoraxiraga/pZXcMyQ/ccna_intro_exam_certification_guide.pdf
    • https://putofikanavo.weebly.com/uploads/1/3/0/7/130738484/wureba.pdf
    • https://tovozilulu.weebly.com/uploads/1/3/0/8/130873983/jabalosab.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/sisaxu/2013426701.pdf
    • https://s3.amazonaws.com/zowejunef/photive_bluetooth_speaker_review.pdf
    • https://uploads.strikinglycdn.com/files/99ae0639-c0a8-4227-8d7e-037428d3a519/resumen_del_libro_el_principito_capitulo_15.pdf
    • https://uploads.strikinglycdn.com/files/ad82ff8e-b0d6-49f0-b8bf-ffd17d543c4d/49064028964.pdf
    • https://s3.amazonaws.com/wuwabobujasivor/goxitufagutije.pdf
    • https://22449060-8e30-4723-8828-967625cce342.filesusr.com/ugd/eddc50_8e4a4f33712448aba6e6280cce18afcd.pdf?index=true
    • https://s3.amazonaws.com/pegozegi/30533806034.pdf
    • https://d45380bd-a93d-4ef2-b2bd-4c7806d1f6db.filesusr.com/ugd/5d2cf3_9ca73d4426bf4eb88f22a72410669036.pdf?index=true
    • https://uploads.strikinglycdn.com/files/89738339-f5f5-45d8-b062-959a6a163838/tojaxu.pdf
    • https://645c32c3-7e99-4959-b93b-7980205539d7.filesusr.com/ugd/30a31c_828d3e1e5fbd464a9519df87400481da.pdf?index=true
    • https://s3.amazonaws.com/nitajosasa/82052207055.pdf
    • https://s3.amazonaws.com/ganubatebedoxez/zakaditigokobumeri.pdf
    • https://s3.amazonaws.com/fukepez/beneb.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e665.bin
393274eb9136620c25deda6b0683b534281b5c29e975b90766253f64c4b35f0d
pdf-font-stream PDF embedded font (sfnt) at offset 0xE665 5088 bytes
font_01_sfnt_off0000f79d.bin
19eedc9dd9ca4c9f8f3bcf0d2f2afb0bf010934efd6aa5a424e2eb0ef0462e9b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF79D 10644 bytes