Malicious PDF — malware analysis report

Static analysis result for SHA-256 e08b2214c301a7d5…

MALICIOUS

PDF

76.0 KB Created: 2021-04-03 13:05:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a03e7fde362ab85b8100bb6acc55dc12 SHA-1: 21d3d6fcd1e92f07e0c9a0c9e5bd2b20aaa55ff3 SHA-256: e08b2214c301a7d5fce4d81f532d2bbd544ff96ec668ca2924bc5159b68b0781
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The PDF contains a large number of external links, flagged as a 'PDF_SEO_LINK_FARM', suggesting it's designed to drive traffic to other sites or potentially host malicious content. One of the primary external URIs identified is https://xezojetit.ru/strik, which is likely the main malicious destination.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=the+redemption+song
    • http://mebelrostov.ru/didi_rider_app_australia575wh.pdf
    • http://ceiling48.ru/vector_watch_lunan9eqs.pdf
    • http://policyhelpcenter.com/when_does_my_puppy_get_better6ryrj.pdf
    • http://nemugub.mywebcommunity.org/programa_arquitectonico_de_un_centro_cultural.pdf
    • http://jopkapopka.online/ariens_rocket_7_tiller_carburetorft2wn.pdf
    • http://lastmarkt.ru/zaxekiwojidifitigiwafaj273.pdf
    • http://fruit-ital.space/30215423144q4vmg.pdf
    • http://pufivuziviv.mypressonline.com/58114496623.pdf
    • http://changepass.online/ukulele_strumming_patterns_4_4d4fg6.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://3f46bf15-0a8c-4e80-b3e5-a2e3bf90e008.filesusr.com/ugd/8e6e76_048c6647d9264a878f96b0783d9c5f70.pdf?index=true
    • http://tebaputazaxuva.myartsonline.com/antigona_rozbor.pdf
    • https://s3.amazonaws.com/bededuxotulapil/what_do_you_put_in_a_smoothie_besides_fruit.pdf
    • https://a161ff94-1a6f-4367-b6f8-8e513a5e676d.filesusr.com/ugd/4c7633_b348ac32ec7e4d0e9b87ed89ca8ddec9.pdf?index=true
    • https://ff0b3df2-dc61-4aeb-9024-93fa9b5bc175.filesusr.com/ugd/aa14a9_9bf74ffcbe9044a3ab983d8b40123829.pdf?index=true
    • https://s3.amazonaws.com/fakuguvil/76226257077.pdf
    • https://s3.amazonaws.com/paxuvagal/44606211269.pdf
    • https://s3.amazonaws.com/nuxulikiwab/general_pathology_questions_and_answers.pdf
    • http://minivenema.atwebpages.com/84490503877.pdf
    • https://s3.amazonaws.com/bisegilupuf/nejonumonoduputavasilo.pdf
    • https://s3.amazonaws.com/jiwotarotavuz/47908247758.pdf
    • https://s3.amazonaws.com/nuxulikiwab/zodemozasu.pdf
    • https://9d349da1-218b-4b59-9e37-2a90cab56d40.filesusr.com/ugd/de9003_378e7f94ec5746f0a45c5a67146c0503.pdf?index=true
    • https://s3.amazonaws.com/rodiligarexo/game_archery_world_champion_3d_mod_apk.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb2f.bin
94ca58fc3d656dd016fa70d9c9a581daadc89dcc00e5933c05a1fb5661c05b6f
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB2F 5080 bytes
font_01_sfnt_off0000fc49.bin
c977b6a466bf8201e9feed6415b7c1834b96239f8279bd843162a3ccf44ef29c
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC49 11308 bytes