Malicious PDF — malware analysis report

Static analysis result for SHA-256 e77a67654104f4b6…

MALICIOUS

PDF

93.3 KB Created: 2021-06-12 02:37:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 0dbc99f2835320cbee06cded508b715f SHA-1: 27fefb9d6c70e65bc13096b96577aa1812be9bfa SHA-256: e77a67654104f4b69a6d4d2c5c911777a39454693ff8e915e2b6c8117f8e3728
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is identified as a malicious PDF by multiple heuristics and a machine learning classifier. It contains a large number of external links, many of which are likely part of a link farm designed to direct users to malicious websites. The primary malicious URL identified is crysiq.ru, which is likely used to host phishing content or further malware. No scripts were extracted, but the PDF structure and heuristics strongly suggest a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crysiq.ru/pbw?utm_term=dhyan+sutra+osho+pdf PDF link annotation
    • https://viwajojavejad.weebly.com/uploads/1/3/1/8/131858172/sopodudijojaxeka.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4386365/normal_60bbfad2ea059.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4476434/normal_5fdf9de46ac4d.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4417653/normal_5fccb7a207267.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455657/normal_606a724c80e0b.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4420745/normal_5ff309cb732e7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4478928/normal_60314a1022b14.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4421466/normal_5fc886fb9fc57.pdfIn PDF document text
    • https://bunafigokakataw.weebly.com/uploads/1/3/0/9/130969192/pijopafuzesutixiw.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4530429/normal_602eaa9ca6276.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4414353/normal_5fcc3ae919596.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://uploads.strikinglycdn.com/files/a2a3cf13-eb48-4ea6-9665-cd68e7cb3a69/30491690188.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ad398528-0b90-4f0d-84cc-e4e971138e00/appion_g5_twin_for_sale.pdfIn PDF document text
    • http://xoxafepapesu.pbworks.com/w/file/fetch/144582534/tovosoluxifuvimititi.pdfIn PDF document text
    • http://tujedet.pbworks.com/f/mukete.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/395e853a-a4a4-4e52-9342-f358da609d60/how_to_use_a_commercial_electric_voltmeter.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f54d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF54D 3764 bytes
SHA-256: 48076f5e2f1c1875197c9664b98d7bccfa5277a4b30c16348a118c096aa1c86c
font_01_sfnt_off000102b2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x102B2 4912 bytes
SHA-256: b1f5eaadeb31c92512a8732e7f967eaea65df1fa2cc8b368b5040691bfb2931a
font_02_sfnt_off00011358.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11358 10548 bytes
SHA-256: 88ecb9beaaa5d511304c25ad0953485f942483c2a9b6630eb78adbc26c8207c9
font_03_sfnt_off00013698.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13698 16060 bytes
SHA-256: 2cca29575edef7a9880cf400a7847cc5df22ba1ee7edc19c7b9bafe603f6c979
font_04_sfnt_off00014b31.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14B31 4324 bytes
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
font_05_sfnt_off00015932.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15932 3840 bytes
SHA-256: 5be7f8cb61c597f0c00779d317702cb5395bb62c5151079888a8436c4e484276