Malicious PDF — malware analysis report

Static analysis result for SHA-256 f268c8226d2891cf…

MALICIOUS

PDF

77.1 KB Created: 2021-05-24 21:58:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f0f5b61b4d5cbd3b46b1c8fce9128dd8 SHA-1: d78357e3c330afa153dfdd33066ae9d51f300981 SHA-256: f268c8226d2891cfcf0a06c949b6963084b0516552a9a8f6965c5eedf1c65f5a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to S3 buckets, suggesting a link farm or a method to distribute further payloads. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as phishing. The document body, though heavily garbled, contains keywords like 'customer ageing report' and 'sap tcode', which are likely lures to entice users to click on the embedded malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=customer+ageing+report+in+sap+tcode
    • https://cdn-cms.f-static.net/uploads/4460457/normal_60198be37798f.pdf
    • https://cdn-cms.f-static.net/uploads/4502178/normal_5fdbecfad5868.pdf
    • https://jerejadudet.weebly.com/uploads/1/3/0/7/130738914/pukiwekizi-fovagigimobodo-tiwataludil.pdf
    • https://cdn-cms.f-static.net/uploads/4391621/normal_6064f50b71dc7.pdf
    • https://gipulafu.weebly.com/uploads/1/3/4/4/134442702/1430048.pdf
    • https://cdn-cms.f-static.net/uploads/4486033/normal_5fdc0a4b896a8.pdf
    • https://cdn-cms.f-static.net/uploads/4366357/normal_603ec41898e69.pdf
    • https://wovovude.weebly.com/uploads/1/3/1/3/131397940/ximosurujuw.pdf
    • https://static.s123-cdn-static.com/uploads/4456387/normal_5ff674b3dbd96.pdf
    • https://tumurotijom.weebly.com/uploads/1/3/4/5/134512141/f79e451b7.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/nakuzafol/wubuzufesuduziwobuwemef.pdf
    • https://s3.amazonaws.com/wetevali/zonewitibilonot.pdf
    • https://s3.amazonaws.com/sefabe/sosuxaxebofotudafamid.pdf
    • https://s3.amazonaws.com/dapekufoxiraku/appointment_letter_natok_all_song.pdf
    • https://s3.amazonaws.com/jutenojamega/smart_waste_management_using_iot_project_report.pdf
    • https://s3.amazonaws.com/zalisujezajaje/the_cat_in_the_hat_full_movie_free_online.pdf
    • https://s3.amazonaws.com/defipedibe/formation_ergonomie_au_travail_pour_non_ergonome.pdf
    • https://s3.amazonaws.com/vukumesoj/tosanifakuloraruluje.pdf
    • https://s3.amazonaws.com/memobofilenabon/bendy_in_nightmare_run_ios.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e48e.bin
8f1e3ed8219dfeb0a990f54e2478ed49121cd72b71328f08e86726095bc77914
pdf-font-stream PDF embedded font (sfnt) at offset 0xE48E 3428 bytes
font_01_sfnt_off0000f0c6.bin
80008178038ec4c49484838ebc1b8b48f1616e68e0be0477aa26e270b2a1cff8
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0C6 5264 bytes
font_02_sfnt_off0001028f.bin
52a57a85ce1cdcf04aa19ba7a76bf3169a7b43bfa8bb71950140dbb199155ab3
pdf-font-stream PDF embedded font (sfnt) at offset 0x1028F 10544 bytes