Malicious PDF — malware analysis report

Static analysis result for SHA-256 b846111693b5f28c…

MALICIOUS

PDF

77.1 KB Created: 2021-03-16 12:40:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bac1095291b335581b92e2a4c69ada97 SHA-1: b9901b44fcdb07db164011903b1dbd7e68ad5001 SHA-256: b846111693b5f28c8286419098e35d9ebdb52238ec8c9c77211c4e7d6c3aa45f
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF contains heuristics indicating it is a link farm and a phishing lure, with a high ML score and ClamAV detection. The document body, though partially corrupted, suggests a financial analysis context. The embedded URL 'https://zajinet.ru/wix?keyword=cash+flow+statement+analysis+pdf' and the first URL from the link farm 'http://sazojojuw.rf.gd/pawuxelosofajuf.pdf' are the highest priority IOCs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=cash+flow+statement+analysis+pdf
    • http://xubanapirobula.mypressonline.com/which_city_is_less_cold_in_canada.pdf
    • http://danivufulof.iblogger.org/61573916342.pdf
    • http://lebojabufi.medianewsonline.com/what_do_you_wear_to_a_garden_party_wedding.pdf
    • http://zunuruxeguxifi.mygamesonline.org/logitech_k120_wired_usb_keyboard_review.pdf
    • http://zawugudumi.getenjoyment.net/painting_kitchen_cabinets_gray.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://sazojojuw.rf.gd/pawuxelosofajuf.pdf
    • https://edcb5511-827b-40b0-97c1-3499c313f96b.filesusr.com/ugd/0779a3_7776669cad2241299b7750eae448d9c0.pdf?index=true
    • http://wugujub.onlinewebshop.net/moultrie_mcg-13034_manual.pdf
    • https://s3.amazonaws.com/xoferuzu/7067342754.pdf
    • https://s3.amazonaws.com/belapawerezuju/43838816560.pdf
    • https://s3.amazonaws.com/daniwodug/gba_roms_free_coolrom.pdf
    • https://171e2b11-24ea-4535-acac-f971ec821c4b.filesusr.com/ugd/a07927_3a4185f379cc4299b1d8e863ead38175.pdf?index=true
    • https://s3.amazonaws.com/tapelu/avg_antivirus_free_with_activation_key.pdf
    • https://6632aaff-1fe9-4f1d-acb3-7d444e457837.filesusr.com/ugd/ce4b7c_75280096829c488b8866ead0837df593.pdf?index=true
    • http://totuxivez.onlinewebshop.net/articles_rules_download.pdf
    • http://zusaxadixuxot.myartsonline.com/vinineregedopezo.pdf
    • http://juripijesem.rf.gd/ginakoludi.pdf
    • http://nupuzasig.epizy.com/literuwujokotibuveso.pdf
    • https://s3.amazonaws.com/rodakarugupoko/where_can_we_see_christmas_lights_near_me.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f1fe.bin
9082d682a9dea573079919643b42b6fe0c6357bce776a7807243204b2e57a6ee
pdf-font-stream PDF embedded font (sfnt) at offset 0xF1FE 5284 bytes
font_01_sfnt_off000103ee.bin
418e9768367009f722fdc5d2238cd45253ce719d9f2299b431331ef1c1751569
pdf-font-stream PDF embedded font (sfnt) at offset 0x103EE 10408 bytes