Malicious PDF — malware analysis report

Static analysis result for SHA-256 b815bef537820a37…

MALICIOUS

PDF

94.7 KB Created: 2021-03-11 23:54:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7153a344429204fff1999f435e41a7f5 SHA-1: 9d42ee7a1d9e0e8c8d4b9cc6e13651736c45989f SHA-256: b815bef537820a37f6dbd95f1093fea5504743683a1c389766f7cfd98f19bc3a
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, characteristic of a link farm, and is flagged by ML classifiers and ClamAV as malicious. The heuristic 'SE_ADVANCE_FEE_SCAM_LURE' strongly indicates a phishing attempt related to prizes or parcels. While no scripts were explicitly extracted, the PDF structure and link farm suggest it's designed to redirect users to malicious websites for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/award?keyword=effects+of+globalization+on+business+pdf
    • https://cdn-cms.f-static.net/uploads/4462038/normal_6036e15a9b817.pdf
    • https://rofoxanubojinud.weebly.com/uploads/1/3/2/7/132740779/pimibeluzore.pdf
    • https://rogefuza.weebly.com/uploads/1/3/4/6/134688393/vubugugelu.pdf
    • https://cdn-cms.f-static.net/uploads/4485152/normal_600d7aa5723b0.pdf
    • https://jiresuzava.weebly.com/uploads/1/3/4/7/134706808/zoligok-tibal-bumam-lamadasabosa.pdf
    • https://tivifetanesa.weebly.com/uploads/1/3/5/3/135347176/4421681.pdf
    • https://static.s123-cdn-static.com/uploads/4426416/normal_5ff781c94dc4e.pdf
    • https://xisuludibu.weebly.com/uploads/1/3/5/3/135300694/xomijevizepa.pdf
    • https://sazeduxawi.weebly.com/uploads/1/3/2/6/132695343/kazun_xopukulazo_lugirum.pdf
    • https://ditoleruv.weebly.com/uploads/1/3/5/3/135345680/7374254.pdf
    • https://dujomimip.weebly.com/uploads/1/3/6/0/136086420/lejove.pdf
    • https://static.s123-cdn-static.com/uploads/4485161/normal_5ff612b482819.pdf
    • https://static.s123-cdn-static.com/uploads/4387929/normal_5ff1b1a89db85.pdf
    • https://puduwuxibipufu.weebly.com/uploads/1/3/5/9/135966859/voxigu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/dazinibonofobi/55441945854.pdf
    • https://s3.amazonaws.com/bevekizadoxuj/73347296344.pdf
    • https://s3.amazonaws.com/fedufiporara/63025711638.pdf
    • https://s3.amazonaws.com/gagagakigibapo/what_is_the_best_version_of_python_to_use.pdf
    • https://s3.amazonaws.com/rimepusox/zefakodomebiwoxoxaf.pdf
    • https://s3.amazonaws.com/tikofaketonub/12952320486.pdf
    • https://s3.amazonaws.com/rurosaveruk/life_cycle_of_a_flowering_plant.pdf
    • https://s3.amazonaws.com/fokapikow/wazodafapujoma.pdf
    • https://uploads.strikinglycdn.com/files/6a46f36b-6292-4141-93fd-e3f159edf626/the_boy_in_striped_pajamas_characters.pdf
    • https://uploads.strikinglycdn.com/files/6991a8a5-02c4-4044-8913-805f7600b2a3/attack_on_titan_season_2_netflix_canada.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00013671.bin
a838729bdee000b8d8a796cee19bfd998ddebec4afbf3332491afe79306afa9e
pdf-font-stream PDF embedded font (sfnt) at offset 0x13671 5376 bytes
font_01_sfnt_off000148dc.bin
15c131781ca12e8386e2f99187042b0e4dcf15651befc746f653ad0df51e2bb5
pdf-font-stream PDF embedded font (sfnt) at offset 0x148DC 10672 bytes