Malicious PDF — malware analysis report

Static analysis result for SHA-256 f29a24848576aba8…

MALICIOUS

PDF

83.2 KB Created: 2021-03-12 06:48:30 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e5148a5f0b3333ef3b3c08b76637577a SHA-1: e9fa5ef371dd710723ed15882112a3b3253864fe SHA-256: f29a24848576aba8840ac707b96d828c16575b40a2ee46f6ef53cf5a5d188ed8
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are SEO-optimized, suggesting a link farm or phishing attempt. The primary URL, 'https://zajinet.ru/award?keyword=mind+reader+by+lior+suchard+pdf', is presented as a lure. While no scripts were explicitly extracted, the PDF structure and numerous external links strongly indicate malicious intent, likely for initial access via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/award?keyword=mind+reader+by+lior+suchard+pdf
    • https://cdn-cms.f-static.net/uploads/4376379/normal_6041e52ee4e8a.pdf
    • https://cdn-cms.f-static.net/uploads/4486535/normal_6040353422b7e.pdf
    • https://cdn-cms.f-static.net/uploads/4374372/normal_5fd9d695d3dc9.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/zibenoroduzuw/ingles_gramatica_facil_vaughan_descargar.pdf
    • https://s3.amazonaws.com/wibedubosateg/indian_actors_hd_images.pdf
    • http://wegatanubuguze.rf.gd/fundamental_mathematical_statistics_gupta_kapoor.pdf
    • https://uploads.strikinglycdn.com/files/cd084e70-de28-4b97-a413-a2319522bdf2/60073361146.pdf
    • https://uploads.strikinglycdn.com/files/1eacc1c2-3c79-49ee-9056-20cb789431e0/obra_literaria_el_si_de_las_nias_resumen.pdf
    • https://s3.amazonaws.com/tamobalasu/81129595003.pdf
    • https://uploads.strikinglycdn.com/files/1ff589be-3362-4649-a130-23973b877627/sunbeam_heating_blanket_flashing_red_light_on_high.pdf
    • https://uploads.strikinglycdn.com/files/f12bd72a-76f6-4f86-b681-41058cadd770/51568384169.pdf
    • https://s3.amazonaws.com/nezanurugega/80894712323.pdf
    • https://9526c93a-d340-4dca-b5fd-2864ff0888c4.filesusr.com/ugd/4c3d6a_278a1b3ef75a4eac9c691753405ddf81.pdf?index=true
    • https://uploads.strikinglycdn.com/files/d372c533-3c63-4a98-92f0-ca5e145422db/massey_ferguson_65_parts_for_sale.pdf
    • http://mojofukiw.epizy.com/47144070553.pdf
    • http://ruriwujuvuwa.epizy.com/61670848630.pdf
    • https://uploads.strikinglycdn.com/files/40f3c577-51e8-4552-aa0b-37c0d802608a/minixewipepezameje.pdf
    • https://436240a4-ef10-404e-ad90-c5cab949c7af.filesusr.com/ugd/3fb742_cd1521fd6ff044a2b7d8a4c346b2b973.pdf?index=true
    • https://s3.amazonaws.com/waxapoz/kerala_blasters_kit_and_logo.pdf
    • https://uploads.strikinglycdn.com/files/1edc23bb-06eb-4e99-ac52-bf417c2d450a/beats_by_dre_wireless_headphones_studio_3.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001099f.bin
84fa252153b06bedef8e3e15b8edc53350fff0353cad3ba6a0d5331667b3103e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1099F 5488 bytes
font_01_sfnt_off00011c4e.bin
ab1d8fedd74197591dd955c02c2905b6f22afe4a3af670b41681b5f9e014153e
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C4E 10456 bytes