Malicious PDF — malware analysis report

Static analysis result for SHA-256 d02ee9f2ee1b24e5…

MALICIOUS

PDF

79.5 KB Created: 2021-03-24 07:49:37 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3fd3120d190c325c9296f301508a588c SHA-1: 56fe2a5de12c698d207e72aa0430ee51d645765b SHA-256: d02ee9f2ee1b24e57c21dfaa3f10fe2f2a4e34f7c9876eb45c038511f0661f04
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, flagged as a 'PDF_SEO_LINK_FARM'. One of these links, 'https://jumiwimov.ru/strik?utm_term=be+here+now+ram+dass+paperback', is identified as an external URI and is likely the primary malicious lure. The ML classifier and ClamAV detection strongly indicate malicious intent, consistent with phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=be+here+now+ram+dass+paperback
    • http://tehnikator.ru/1105739659954ncd.pdf
    • https://cdn-cms.f-static.net/uploads/4462368/normal_603d1d5c67cde.pdf
    • https://cdn-cms.f-static.net/uploads/4492294/normal_5fe9ae0a0439b.pdf
    • http://lnstagram-helping.live/comcast_ref_code_s0a00_after_power_outage4d6s8.pdf
    • http://hytri.com/metformin_hcl_1000_side_effectshv8yf.pdf
    • http://prizinsta365.online/building_cheats_for_sims_4_pcjdqcy.pdf
    • https://cdn-cms.f-static.net/uploads/4448129/normal_6033bd78a978a.pdf
    • https://cdn-cms.f-static.net/uploads/4416496/normal_5fd3ce779fd0e.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/kulinisokakewi/custom_bottom_navigation_bar_android_studio.pdf
    • https://e082b6be-64c0-45f6-a8ff-82b9c6f476f0.filesusr.com/ugd/1479de_ee5ce2de57b14e278f61ab81cb5f3911.pdf?index=true
    • https://s3.amazonaws.com/buxoparadazegu/chamakam_in_kannada.pdf
    • https://s3.amazonaws.com/vufupu/wuzebinonilobep.pdf
    • https://0298dc5a-7924-4276-8279-06452a5288da.filesusr.com/ugd/b30cf0_c9db1740790243fc801ae1315fac1da2.pdf?index=true
    • https://e8ceee85-86bf-4804-80ab-d7a1511cbcf5.filesusr.com/ugd/38650a_83cee60fb04b491d9624e7a40f6798ef.pdf?index=true
    • https://s3.amazonaws.com/duzexefemosaxe/36198443781.pdf
    • https://s3.amazonaws.com/kezemiradigu/ice_hockey_score_sheet.pdf
    • https://4fbc56e1-d9a2-4996-be1d-38f9cd263936.filesusr.com/ugd/b1afee_86c9f69ff47b4140861ff06a7480111b.pdf?index=true
    • https://uploads.strikinglycdn.com/files/831f9a66-a745-40a1-99f1-283553d899fe/pejibixinopofejokitisu.pdf
    • https://s3.amazonaws.com/juzewojavomofew/tusirebuwenivudazodo.pdf
    • https://s3.amazonaws.com/wuvepilamamuse/rapewewitopav.pdf
    • https://s3.amazonaws.com/lejivugeleguwod/bleacher_report_ne_pats.pdf
    • https://uploads.strikinglycdn.com/files/89717a08-5048-49b4-9115-20a310052e10/buffalo_rice_cooker_troubleshooting.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f8a8.bin
d95125a4b2f6486bf47711912311a41ce292cbc5ea5f8ba443c50e846a0d772f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8A8 5624 bytes
font_01_sfnt_off00010ba7.bin
06f7219093fe21425da69ae80f3d34245b735cd462847b7f1f6ec85b351222e8
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BA7 10836 bytes