Malicious PDF — malware analysis report

Static analysis result for SHA-256 20fb8aab4dd9c5e2…

MALICIOUS

PDF

82.1 KB Created: 2021-04-20 18:07:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 157430716d04bea33414c0656d2f4da2 SHA-1: 264135b7609720328964430a7fb627048c996810 SHA-256: 20fb8aab4dd9c5e2094f2f37b8a86d8520fb411886de93d2c574221ed7929b56
244 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF was flagged by multiple critical heuristics for containing malicious redirector links and a large link farm hosted on disposable infrastructure. One URL, 'https://yafferge.ru/strik?utm_term=samsung+smart+tv+board+price', is explicitly identified as malicious. The presence of numerous links, including one to known malicious infrastructure, strongly suggests a phishing or scam campaign designed to lure users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=samsung+smart+tv+board+price In PDF document text
    • http://tiledevaw.22web.org/lojinuvatigegasurop.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://9480ebe7-8096-4165-94d5-b35dd525e9f4.filesusr.com/ugd/07b43d_e6e7497cb25f43fb91675e041bacc8d0.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/1210f440-8af8-41c8-ab57-946348de87bc/linksys_ac1200_extender_re6400.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8d3560b5-8a0c-4c13-aac0-90fa7655435a/14622341718.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6d30f254-c641-49c7-84c6-f343b5c279a5/17794394182.pdfIn PDF document text
    • https://5984e891-aecd-43e6-866f-efdb297c9c35.filesusr.com/ugd/403565_fc12a305f4aa430786282e66c4677d82.pdf?index=trueIn PDF document text
    • http://kiwusumusi.rf.gd/exhibitors_handbook.pdfIn PDF document text
    • http://zosoluvol.epizy.com/dedication_in_internship_report.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c81fb1d4-6683-4b53-8961-d1f0c6616481/how_to_tell_if_skin_is_sun_damage.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/da01b99b-0d6d-4e4b-b1e7-5d416b52c775/78005059909.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/914ea35e-af78-402a-8295-0afa1d1eac2c/cuisinart_dlc-10sy_pro_classic_7-cup_food_processor_watts.pdfIn PDF document text
    • https://s3.amazonaws.com/fibesezati/wwi_trench_warfare_worksheet.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f5fa9438-e95b-4014-8a81-e2919fc00bee/how_many_watts_is_an_average_microwave_oven.pdfIn PDF document text
    • http://surobufalinaxis.epizy.com/4262909543.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dfe2d019-3d5b-47fc-85a8-5bc9527a61c7/17754863548.pdfIn PDF document text
    • https://11fe2947-f393-4df3-905d-f9f3730e834a.filesusr.com/ugd/b1b16e_a67063cf6610437a928e7c9674af7e8a.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/5578c7b5-41eb-477e-9dca-0af820ed4a29/99253115985.pdfIn PDF document text
    • https://s3.amazonaws.com/warapagefasovi/isaiah_rashad_albums.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d63437d8-9923-411e-b2ce-5add805b55b3/motion_offense_vs._2-3_zone_defense.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cd3bce4e-f4cc-4b5d-b1c6-5716e5a084a7/equivalent_ratios_worksheet_7th_grade.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a7665c1d-6f90-4377-92b7-387477e73581/basic_math_formulas_algebra.pdfIn PDF document text
    • https://s3.amazonaws.com/sitozi/a_series_of_unfortunate_events_cast_season_2_episode_3.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ffca.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFFCA 5664 bytes
SHA-256: eb213e8501a462765c55ea27d43e9d6d02073c0db36b452bc93f60d247e5ff0e
font_01_sfnt_off000112ff.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x112FF 11300 bytes
SHA-256: 75492f5eb755bb024cd7abc89b85b328428be0f6037049d51f5427e05c3fc8f3