Malicious PDF — malware analysis report

Static analysis result for SHA-256 bb4c2f1cc0514e1c…

MALICIOUS

PDF

118.4 KB Created: 2021-04-01 10:33:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 28079291aa3298749caa1b6438fbf7f9 SHA-1: 91100abf39f5bc3dd7ff3b3ae420bfe3574219fe SHA-256: bb4c2f1cc0514e1c1d2f723046da78f555352df34ad0e9825613e60bd843ece8
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, with one primary malicious URL being https://xezojetit.ru/wix?keyword=tv+guide+yakima. ClamAV and ML classifiers strongly indicate this PDF is malicious, likely a phishing or SEO poisoning attempt. No scripts were extracted, but the PDF structure itself facilitates the malicious redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/wix?keyword=tv+guide+yakima
    • https://cdn-cms.f-static.net/uploads/4451757/normal_60451348ba0c0.pdf
    • https://cdn-cms.f-static.net/uploads/4375908/normal_5fdc2875ce0a5.pdf
    • https://cdn-cms.f-static.net/uploads/4426972/normal_6030aa7a280f8.pdf
    • http://siondez.ru/nutrition_in_pregnancygi7db.pdf
    • https://static.s123-cdn-static.com/uploads/4383444/normal_5feb81dd14b2a.pdf
    • http://cashtanks.fun/zutesidarilosovuvutgh4o5.pdf
    • http://vikiduxa.mywebcommunity.org/what_type_of_oil_does_lexus_rx_350_use.pdf
    • https://cdn-cms.f-static.net/uploads/4410190/normal_5fd15327c981f.pdf
    • https://static.s123-cdn-static.com/uploads/4469634/normal_5feb77ee8855b.pdf
    • http://vibemezanolex.mypressonline.com/compuestos_azoicos.pdf
    • https://cdn-cms.f-static.net/uploads/4368500/normal_602c8280c1ce0.pdf
    • https://static.s123-cdn-static.com/uploads/4421466/normal_5fccf62ac8fd2.pdf
    • http://tricitysikhs.com/encyclopedia_of_wine_beer_and_spiritsalios.pdf
    • http://itsamorem.com/chander_pahar_story_in_bengali_free_downloade53bb.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://1639490a-f715-481e-9fb1-af38d332269b.filesusr.com/ugd/a59130_4fd2963af55d4e6aafbfa9184e445075.pdf?index=true
    • https://1423d76f-a56f-4481-bf87-726e17039346.filesusr.com/ugd/14aee2_e83b62452d34491da9d4d3f5e566df2a.pdf?index=true
    • https://2ddc7431-ff91-46e9-9708-195efd6cc195.filesusr.com/ugd/ffe0d3_f5e2c114e37147c7aff72db1e5dc3fe4.pdf?index=true
    • https://uploads.strikinglycdn.com/files/52bbf9cb-0a2d-4c63-8503-6528880b6325/netgear_wndr3700v2_repeater.pdf
    • https://uploads.strikinglycdn.com/files/20d1d99b-f13d-4d46-a692-eff07c505e9c/taxemiwigu.pdf
    • https://e7e1611e-f78d-4dfd-b5ce-3be5f579732f.filesusr.com/ugd/4b76a6_967e08b96bcc4b11b9474514c6d47bc1.pdf?index=true
    • https://uploads.strikinglycdn.com/files/f4e523bd-4dcc-4be9-b725-2b838c3b853e/toro_gas_trimmer_carburetor.pdf
    • https://538d8494-0c7d-401a-b890-0485f6bc7bca.filesusr.com/ugd/29c71c_47f1006f0bca46c69904458ba21563e9.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00019128.bin
bbb8721918b74c6a276fe0c8a2533373279f9de40deb513b33156a65779c9326
pdf-font-stream PDF embedded font (sfnt) at offset 0x19128 5012 bytes
font_01_sfnt_off0001a23d.bin
a363647f7f65ea3a259eb952dce91125702e0029cf15ddce8c5588d3e596f60c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A23D 12208 bytes