Malicious PDF — malware analysis report

Static analysis result for SHA-256 b770a2bfeef2ede2…

MALICIOUS

PDF

108.1 KB Created: 2021-03-23 05:05:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 18037ea05bd7dc1c428843728c676606 SHA-1: 7ae15521d031d5d15c85ac7d6004a292f86f2e5c SHA-256: b770a2bfeef2ede22d06bf2e0d5910902bc15e5734517dd8b4267f08f5916753
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains numerous external links, with one pointing to 'xezojetit.ru', suggesting a phishing or malware distribution attempt. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, likely to manipulate search results or distribute malware. Although no scripts were explicitly extracted, the presence of embedded URLs and the overall structure suggest it's designed to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=why+curl+of+gradient+is+zero
    • http://lnstagramverificationbadge.com/twilight_new_moon_full_movie_in_hindi_free_download_utorrentai0of.pdf
    • http://bcpzonasegura10beta-viabcp.com/mapa_espaa_transport_feverop8zy.pdf
    • https://tokuniti.weebly.com/uploads/1/3/4/3/134331772/wokusawapu_genevalud_nomeso.pdf
    • https://febixitojujemo.weebly.com/uploads/1/3/4/4/134402622/watebidematal.pdf
    • http://vorgazme.com/tafsir_ibn_kathir_arabic_downloadqfdws.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/kuxuxemu/rawlinsons_construction_cost_guide_free_download.pdf
    • https://3d7304b5-8527-495f-b913-615d6f357a43.filesusr.com/ugd/ef7486_c59a4775e1fd41a1878d7ff0466f6acd.pdf?index=true
    • https://s3.amazonaws.com/zonebon/80690210465.pdf
    • https://s3.amazonaws.com/laginekux/best_quotes_from_henry_v.pdf
    • https://s3.amazonaws.com/tesodagiwor/bms_college_application_form_2019.pdf
    • https://c31d65df-273c-4bcc-acfb-7b03b0724b99.filesusr.com/ugd/e7e4a0_89a6919e167c4b029f0443876a575819.pdf?index=true
    • https://75edee45-cd08-43cb-a752-0c33e5c2343f.filesusr.com/ugd/a7c173_00d269cef308447f80974e1c2556bd04.pdf?index=true
    • https://s3.amazonaws.com/resisuna/netasetutok.pdf
    • https://s3.amazonaws.com/pilazi/kotarivap.pdf
    • https://7e62deb9-9b1a-4e2d-8b60-9a8f762ee201.filesusr.com/ugd/1f553f_cc7c62a7906d4599bc8d383671ec5112.pdf?index=true
    • https://s3.amazonaws.com/wiremeresegikon/kiwilibovepi.pdf
    • https://uploads.strikinglycdn.com/files/afe9c588-18cd-4d41-ba82-cb8854b0862a/how_to_clean_my_cuisinart_coffee_pot.pdf
    • https://uploads.strikinglycdn.com/files/a4629c91-b0bd-4f8a-aa54-c59a49676431/4106376108.pdf
    • https://uploads.strikinglycdn.com/files/12521eef-c561-4eb0-b7c4-2e0b3f25b76c/vixokubuvu.pdf
    • https://uploads.strikinglycdn.com/files/8664650e-da3d-4b09-b6c1-1669d0b28488/22432134725.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://s3.amazonaws.com/kuxuxemu/r
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00014c18.bin
d9d58b15ad70bbeb8aebb764924297f4f7b3bfe79d660ee158219f2eb2b7a48b
pdf-font-stream PDF embedded font (sfnt) at offset 0x14C18 5448 bytes
font_01_sfnt_off00015eb8.bin
5a4c2b616a84bff0285b713a5e6340f22a9bf6018fc09d38c47ff2b51bb150ff
pdf-font-stream PDF embedded font (sfnt) at offset 0x15EB8 13180 bytes
font_02_sfnt_off00018b41.bin
f5d9d6f91a4964b75e2f70e84a1c8098ac6c9682d8de54e89144f69e9939eebf
pdf-font-stream PDF embedded font (sfnt) at offset 0x18B41 17168 bytes