Malicious PDF — malware analysis report

Static analysis result for SHA-256 19b66d5f3da9040a…

MALICIOUS

PDF

84.8 KB Created: 2021-04-23 16:43:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d9e3e44b85a0f73bb1118be643caef43 SHA-1: d07dd05c3663f6b41be1d250e09a67a0e7c9df06 SHA-256: 19b66d5f3da9040adfa8804ddfeaa4bc194de9802fac6bd7ccece1b7e09fa352
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, indicating a phishing or malware distribution attempt. The embedded URL is disguised as a search query result, a common social engineering tactic. While no scripts were extracted, the PDF structure and the malicious URL strongly suggest a phishing attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=what+are+the+four+main+components+of+the+earth
    • http://mosasekoz.22web.org/90460936143.pdf
    • https://cdn.sqhk.co/xenudipu/hLDgf5a/tikebul.pdf
    • http://sezewadiwun.22web.org/70675972293.pdf
    • https://setejurisu.weebly.com/uploads/1/3/2/7/132740540/bonolukofejir-popewulupiw-kubidudipawo.pdf
    • https://jorevubo.weebly.com/uploads/1/3/4/8/134869484/4298703.pdf
    • https://cdn.sqhk.co/wozejodes/ThhHiaV/radio_italia_lista_musica.pdf
    • http://balenagawovu.22web.org/99047560303.pdf
    • https://cdn.sqhk.co/wopidevepip/SWbYjcf/47938024076.pdf
    • https://cdn.sqhk.co/xupodafib/gho7iLV/mojo_story_maker_for_instagram.pdf
    • https://cdn.sqhk.co/sowojusawepu/ivvyPBO/dirty_furnace_blower_motor.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://gizufaw.epizy.com/manuel_altistart_48.pdf
    • https://203e7bc3-08d7-4ecc-a8df-f797e0d4a079.filesusr.com/ugd/d4579c_aa8a0d2bb9554ffbbf3d8030312fb337.pdf?index=true
    • https://uploads.strikinglycdn.com/files/f24847fe-69d0-4257-a7b2-1c5f81c6b8a3/what_is_the_social_darwinism_theory.pdf
    • https://uploads.strikinglycdn.com/files/0f5e91ca-f464-4975-83ae-c2836b0d6d5f/39726711113.pdf
    • https://uploads.strikinglycdn.com/files/a7d32015-74b3-4b33-bd90-3ca168971e6f/why_is_indian_peace_commission_important.pdf
    • http://gajoruza.epizy.com/70736882384.pdf
    • https://4a0f17ac-6ce6-4c05-9546-25c48d39d9f7.filesusr.com/ugd/cd79e3_f6ff56d10a394b73bad7c1fd3ae55b75.pdf?index=true
    • https://8bd4fa4f-8da4-4ebc-9486-d6514ce9660e.filesusr.com/ugd/a64c8c_1f858f04b75843e5b34f1c980115c55b.pdf?index=true
    • https://80b1f93a-fe74-4439-a81d-34814fa7a505.filesusr.com/ugd/e56fe2_ad2038e420d3487189b2deac3e46cbd6.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fbaa.bin
b1974c6271d5d0252969d32b2b91e2cbe7797f6fc2dd06bd0647b8210ddd940c
pdf-font-stream PDF embedded font (sfnt) at offset 0xFBAA 5116 bytes
font_01_sfnt_off00010cf8.bin
b3e56b11d107ef5885cee685bec64e24057da76899eb3599e4b663b749e9b12f
pdf-font-stream PDF embedded font (sfnt) at offset 0x10CF8 12372 bytes
font_02_sfnt_off00013738.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x13738 4324 bytes