Malicious PDF — malware analysis report

Static analysis result for SHA-256 f38b9ee318739369…

MALICIOUS

PDF

77.3 KB Created: 2021-03-28 12:22:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7a7408bb0d3dcf454db2a2fb870fb595 SHA-1: 7ee6f3cd86318f42dbf1f6b36f9ec208b9f78888 SHA-256: f38b9ee318739369fa9fd0e8f5f1f34c30a7dced7712d7a2ba77a5c753068e7e
236 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF contains numerous external links, with a significant number pointing to Weebly domains, suggesting a link farm or distribution network for malicious content. The 'Advance-fee lottery/parcel scam lure' heuristic indicates a phishing or scamming attempt. The presence of 'cmd_commands_list_files.pdf' and associated URLs, along with the ML classifier and ClamAV detections, strongly suggests malicious intent, likely involving the execution of further payloads or redirection to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 7

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/123?utm_term=bleacher+report+football+live+stream
    • https://golotarati.weebly.com/uploads/1/3/1/8/131856611/1ae0ef793ec6.pdf
    • http://weraka.online/zawawivunidw5oja.pdf
    • https://limofagis.weebly.com/uploads/1/3/4/6/134640762/4872039.pdf
    • http://sale50.pro/adobe_writer_for_windows_10nhgfs.pdf
    • https://buvekidi.weebly.com/uploads/1/3/0/7/130775196/a4cab16780124bb.pdf
    • https://guvepilafofifiv.weebly.com/uploads/1/3/4/6/134682232/3311abb2fd89.pdf
    • https://xudidetopos.weebly.com/uploads/1/3/4/5/134579215/ruxivajosa-gerixoxexefi-javinokuruxude-zegipepuni.pdf
    • http://prizinsta24.space/96190160609f8qdl.pdf
    • http://reduslim-italy.site/89281167102nu1zd.pdf
    • https://xumodaniteged.weebly.com/uploads/1/3/4/4/134480563/6d759c38230.pdf
    • https://xowasesulozuvuv.weebly.com/uploads/1/3/5/3/135347394/wewapi-milidiso.pdf
    • https://xumodaniteged.weebly.com
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/ee07b627-990a-4c17-9e8d-02b7da19a582/79230129723.pdf
    • https://s3.amazonaws.com/gixawetopoli/introduction_to_law_and_the_legal_system_11th_edition_download.pdf
    • https://4454cc88-256b-48ad-9013-c0414c72072d.filesusr.com/ugd/67e251_69700448ced142c2a0bb7538096c90fc.pdf?index=true
    • https://s3.amazonaws.com/jeduzizonox/85403085607.pdf
    • https://5e3b32e6-a537-4a58-a531-ef303a468713.filesusr.com/ugd/120874_ea63e24239b14e4980262712817587a3.pdf?index=true
    • https://c6f55193-7475-4343-97dd-33cb3b141b6a.filesusr.com/ugd/808d8c_332006ab9f5e48479534e29135a63612.pdf?index=true
    • https://abaaaae4-9231-44fc-b12c-ad55ebcc68e7.filesusr.com/ugd/2ca09c_933a2ce863c64c6eb2ae1c5f36cd4a87.pdf?index=true
    • https://uploads.strikinglycdn.com/files/005fda67-4e09-4e8c-9330-f3aeb735493d/basic_guitar_chords_finger_placement.pdf
    • https://uploads.strikinglycdn.com/files/8cb80cf7-a0e9-40a5-a73d-655f9613772c/windows_cmd_commands_list_files.pdf
    • https://95043331-d9de-4498-ad98-35b8ac3ee23f.filesusr.com/ugd/5740b2_5e9849b9e46b43859bef9865eccb6024.pdf?index=true
    • https://uploads.strikinglycdn.com/files/8e2d773a-3403-452f-aadb-5b9fdc4ea6f8/72071390228.pdf
    • https://s3.amazonaws.com/xedewofuretujo/what_was_the_central_theme_that_enlightenment_thinkers_were_writing_about.pdf
    • https://uploads.strikinglycdn.com/files/5b17f533-d2c2-4375-a407-1835f52a3332/3193130627.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eeae.bin
42e8bcb6d98861b8d70c6b638821aa8d620371dc5b0a84986d58cacdf78b2a16
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEAE 5504 bytes
font_01_sfnt_off00010141.bin
79e0086d5c95bde1ef9cc55156b5924122946e2d505b630458b3e7be73fc79db
pdf-font-stream PDF embedded font (sfnt) at offset 0x10141 11268 bytes