Malicious PDF — malware analysis report

Static analysis result for SHA-256 d2b99291d7dea296…

MALICIOUS

PDF

82.4 KB Created: 2021-03-20 16:40:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e22fff9de58efd36548d243fdf053bc3 SHA-1: 78349f53e3c7a2b7dd0a09700b6fdde27f090ad5 SHA-256: d2b99291d7dea296005621f2002f880bbf4b6884d90d378a51480ab4cb258f24
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO manipulation tactic. One of the embedded URIs, https://kuzutuzo.ru/strik?utm_term=sennheiser+ew+100+g4-me2%252F835-s-a, is flagged as suspicious. While no scripts were explicitly extracted, the PDF structure and the presence of numerous external links indicate a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=sennheiser+ew+100+g4-me2%252F835-s-a
    • http://gebevojika.mygamesonline.org/87623201547.pdf
    • https://fojugifobuko.weebly.com/uploads/1/3/5/3/135328464/vakago-vebulowobudi.pdf
    • https://sulagumafiwez.weebly.com/uploads/1/3/1/3/131383207/1398481.pdf
    • https://cdn.sqhk.co/jukelifawap/BNihB47/radionorba_app_italia_free_online_download.pdf
    • https://gokepitamewema.weebly.com/uploads/1/3/5/3/135325242/dikewuk_kufiketubexa.pdf
    • https://cdn.sqhk.co/parikozug/jbqgLq5/1198259070.pdf
    • http://rexuwoxaga.sportsontheweb.net/bunanoninanilosu.pdf
    • https://cdn.sqhk.co/xagaxubibiz/gCgjhdc/regoseniparula.pdf
    • https://werovowota.weebly.com/uploads/1/3/4/7/134766705/fasewe.pdf
    • https://cdn.sqhk.co/moleselofa/f7x3ohe/66357786778.pdf
    • https://cdn.sqhk.co/dofofigeniso/0jas7e0/rocketman_full_soundtrack_youtube.pdf
    • http://porizaritofo.mypressonline.com/gatawisimitipax.pdf
    • https://mavuzoxawajike.weebly.com/uploads/1/3/0/9/130969593/desito-begepipaladovum.pdf
    • https://cdn.sqhk.co/sobupepokor/eQKhhzu/diy_dice_tray_cigar_box.pdf
    • https://cdn.sqhk.co/dukasavubu/hbhatxM/gokesikizasizipu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/xapidajovaji/college_algebra_practice_test_with_answer_key.pdf
    • https://s3.amazonaws.com/belapawerezuju/viper_anti_plagiarism_software_free.pdf
    • https://s3.amazonaws.com/zexozavo/41801418793.pdf
    • https://s3.amazonaws.com/zufaxepixiguxax/which_word_or_phrase_should_replace_indisputably_proves_to_create_an_objective_tone_suggests.pdf
    • https://s3.amazonaws.com/wavunot/oecd_action_6_final_report.pdf
    • https://a121017b-3fb3-450c-9156-48dd71a9bf80.filesusr.com/ugd/07625c_3404576834794769a1bd133a8af43a9e.pdf?index=true
    • https://ecab545c-19d2-4654-b6ac-fb8b9749f5ba.filesusr.com/ugd/e5412a_1ba4848b7be64c20b12271ae4a628dcd.pdf?index=true
    • http://fajazimigig.atwebpages.com/how_to_fix_air_conditioner_leaking_water_outside.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f908.bin
3ecba298227a8aee3bfb7efd76e0a18dbb7624a98287711be4cf6d8abbfcb6ba
pdf-font-stream PDF embedded font (sfnt) at offset 0xF908 6228 bytes
font_01_sfnt_off00010e37.bin
7c9ff0ecd6e655e22664ce99bbe67bd4656c6ae336f3c865005eedd1b14f9d32
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E37 16628 bytes