Last Updated: 2022-05-07 16:40:57 UTC
by Guy Bruneau (Version: 1)
I received several PDF like these in the past few days in my ISC mailbox and decided to look at 3 that were very similar. All 3 files are a one page picture with nothing else in it except a URL.
Looking at the first one using Didier's pdfid.py tool:
There is something interesting in all 3 of them, they all have a URL (/URI) embedded in them. Using pdf-parser.py, lets extract the URLs:
What is interesting about all 3 email is they all have the same behavior with the same location /a/. The first 2 URLs do not resolve, only aleksalekss[.]ru resolve to 126.96.36.199 which was recently activated on the 28 March 2022. Several files have been submitted to VirusTotal in the past 4 days with 0 to low detection. None of the 3 files below had any matches (submissions) in VirusTotal.
Indicator of Compromised (IOCs)
Domains & IP