Malicious PDF — malware analysis report

Static analysis result for SHA-256 33c1efc1350a82d2…

MALICIOUS

PDF

77.7 KB Created: 2021-03-14 10:04:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9b62aa43e4eab3a79b768bb680c5f2e6 SHA-1: 2d679d3b90a7124a93a5322fc13d931b6c82fe77 SHA-256: 33c1efc1350a82d29e29772e042a739a8fd1a6335cd47ac7eda59030db421ce0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with heuristics indicating the presence of external URIs and embedded URLs. The document body, though heavily obfuscated, suggests a lure related to 'technical analysis explained fifth edition pdf'. The primary malicious indicator is the external URI pointing to 'https://pelibifir.ru/123', likely serving as a download link for a secondary payload. No scripts were extracted, but the presence of embedded URLs suggests a phishing or social engineering attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/123?utm_term=technical+analysis+explained+fifth+edition+pdf
    • https://cdn.sqhk.co/kewawukufiju/nmsGjcg/1574235994.pdf
    • http://kejamezegujoz.iblogger.org/full_information_about_neet_2018.pdf
    • https://cdn.sqhk.co/nozalodugavi/fjeifCb/95125442052.pdf
    • https://fikijumosoliz.weebly.com/uploads/1/3/5/4/135400707/molexulek.pdf
    • http://bofinaposo.iblogger.org/expense_sheet_xls.pdf
    • http://jomotew.iblogger.org/furefawula.pdf
    • https://cdn.sqhk.co/javeduner/4ggAJgg/champion_of_the_gods_apk_free_download.pdf
    • https://befawiboper.weebly.com/uploads/1/3/5/3/135389238/mejuxewepibapovuv.pdf
    • https://litemavokof.weebly.com/uploads/1/3/1/8/131871991/2886753.pdf
    • http://gupilan.iblogger.org/what_does_good_composition_mean_in_photography.pdf
    • https://segunimumise.weebly.com/uploads/1/3/1/0/131070895/8191936.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://jolagetota.epizy.com/tamil_songs_2016_hd.pdf
    • http://xunepesefosog.rf.gd/vipinudafafafisawaz.pdf
    • http://votarim.epizy.com/levopo.pdf
    • http://pulijivugis.epizy.com/sharp_el-1197piii_ribbon.pdf
    • http://zepurudevivo.rf.gd/66321516947.pdf
    • http://maxefaronuxugur.epizy.com/vobiwasu.pdf
    • http://xokesuluz.epizy.com/cricket_news_video.pdf
    • http://kilobawul.rf.gd/analisis_literario_del_libro_la_familia_de_pascual_duarte.pdf
    • http://duxurulokij.epizy.com/vuwobuzevitamejir.pdf
    • http://ninukak.epizy.com/casualty_tv_show_episode_guide.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f131.bin
68e12a7f6b4f627439545e8097206896e4f541e18152e708634f90a1b1e9b048
pdf-font-stream PDF embedded font (sfnt) at offset 0xF131 5268 bytes
font_01_sfnt_off0001032e.bin
49e5c1c6b99e96a20df84574b5ce7b1a1c5a03eccbfee52106e78092f1288a7b
pdf-font-stream PDF embedded font (sfnt) at offset 0x1032E 11320 bytes