Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec9d2eb41bd63173…

MALICIOUS

PDF

78.1 KB Created: 2021-03-17 18:42:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f4e1468fa922f7904be72c12b3244a5f SHA-1: 96a7c285cdb23e5278fd500b359ff8c54500c94f SHA-256: ec9d2eb41bd63173bd8b13b58101878689fa83efcea276b98eb4ddedd1a81750
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many of which are part of a link farm designed to appear as legitimate SEO content. The primary malicious URL identified is zajinet.ru, which is associated with the keyword 'pubg hack apk android', suggesting a phishing or scam lure. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=pubg+hack+apk+android
    • https://fotizewuzawefuv.weebly.com/uploads/1/3/4/6/134668380/derazepasezixemeza.pdf
    • https://dazuzidasepod.weebly.com/uploads/1/3/2/6/132681566/warukerekegasu_xejoga_tixese_lexojigu.pdf
    • https://zuwukozoxuwiged.weebly.com/uploads/1/3/4/7/134713444/e4c08.pdf
    • http://mikazuxo.mypressonline.com/modern_business_administration_sixth_edition.pdf
    • https://static.s123-cdn-static.com/uploads/4384028/normal_5fdff7bfdec8b.pdf
    • https://static.s123-cdn-static.com/uploads/4490738/normal_5ff551dc169a4.pdf
    • https://xoxulesajoxe.weebly.com/uploads/1/3/1/4/131438427/dewuwod.pdf
    • http://winoxolupuvil.getenjoyment.net/n1996_motherboard_connections.pdf
    • https://cdn-cms.f-static.net/uploads/4428062/normal_6046f3d84c171.pdf
    • https://mogavibebeza.weebly.com/uploads/1/3/5/3/135318512/40c14f06e48c1.pdf
    • http://xalapuzim.sportsontheweb.net/salicilato_de_bismuto.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://d451e762-8e00-4155-9971-9512d28d2528.filesusr.com/ugd/b52961_24f2bfe2ff454136ad6498b9fa040fde.pdf?index=true
    • https://uploads.strikinglycdn.com/files/25973ecf-0794-488b-ba0a-0244f66efc85/18786352217.pdf
    • http://tavamikilav.myartsonline.com/why_is_my_electric_fence_beeping.pdf
    • https://631ffb88-cf2d-4844-8d6b-9338a1b21cc5.filesusr.com/ugd/d24e6f_b842a03a30694d85b5d812c49c5cc3c2.pdf?index=true
    • https://183df7f2-4185-4ca0-bfcc-33b39bc842f1.filesusr.com/ugd/9ac34a_f281d135e2594962982572c07bd549b7.pdf?index=true
    • https://7e005a1c-fb68-43c1-af83-b854b6a2d282.filesusr.com/ugd/dcfb95_4a7860e189544761877c58edea8737ae.pdf?index=true
    • https://cb0920a4-0dfc-4587-8161-bd3bf883b043.filesusr.com/ugd/df391a_3793a3ee0ae342d68bff6d4b5321ac3d.pdf?index=true
    • http://bavufupuvamopaf.atwebpages.com/63903021102.pdf
    • https://uploads.strikinglycdn.com/files/6c793290-8765-4094-8e07-79234681e962/public_relations_and_fundraising_manager_duties_and_responsibilities.pdf
    • https://uploads.strikinglycdn.com/files/badf999a-d40c-4848-9f5f-4998b5a1f64d/46658550183.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f3fd.bin
8abd9b7b0b2d37aadd5f0f92b6c254ff127ce6472ce8437dc9662a49ad6458e3
pdf-font-stream PDF embedded font (sfnt) at offset 0xF3FD 5328 bytes
font_01_sfnt_off00010614.bin
5a304d49b458538d56c449ee6181e57738356b8a0875f0219aac50fd53f7577f
pdf-font-stream PDF embedded font (sfnt) at offset 0x10614 10936 bytes