Malicious PDF — malware analysis report

Static analysis result for SHA-256 61400146dc327e6a…

MALICIOUS

PDF

75.8 KB Created: 2021-03-08 19:57:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 843eb968510dec2cac60d71e5335cbad SHA-1: 229c97ee2063d04cd5a1b88d2ab1d2f3de9ddd77 SHA-256: 61400146dc327e6a3b69e1a16c39c2a22602fec2acbd192fd20d8c1f1fb8149a
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link, directing users to 'https://yafferge.ru/strik?utm_term=2020+kx100+price'. This indicates a phishing attempt, likely designed to lead the user to a malicious site. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, but the presence of a malicious URL is sufficient evidence for a phishing attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=2020+kx100+price
    • https://jimigafekalese.weebly.com/uploads/1/3/1/4/131407537/guvuxazorezifa-vajitoza.pdf
    • https://paporese.weebly.com/uploads/1/3/1/0/131071113/edb8740fbf8f4.pdf
    • https://fakebomazeb.weebly.com/uploads/1/3/1/4/131453402/bugozi_wijisujut_fosowifof.pdf
    • https://giboritozi.weebly.com/uploads/1/3/1/3/131379296/notifevitobu.pdf
    • http://itsamorem.com/mai_tai_diffords_guidekk7s5.pdf
    • http://keto-menu.online/rijaxbp1gh.pdf
    • http://verenica.net/bizarawuzibevumueoe2y.pdf
    • http://gatorama.site/alpha_lipoic_acid_review78snr.pdf
    • http://tumexade.22web.org/vimuk.pdf
    • http://honey-love.ru/abecedario_en_letra_de_imprenta_mayuscula_y_minuscula_para_imprimir6nr3g.pdf
    • https://fepafevadaxajaw.weebly.com/uploads/1/3/4/0/134095897/rozipeluge.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/a2d7a646-8efc-4b45-b3af-341236ce886f/22921618433.pdf
    • https://s3.amazonaws.com/bopuxosavubare/mutinezukimutoburonumivo.pdf
    • https://uploads.strikinglycdn.com/files/01a2e26b-5425-4dbe-aba0-d2a703570be5/romeo_y_julieta_reserve_review.pdf
    • https://ba30dffa-51fe-4caa-9472-6f142403a9bb.filesusr.com/ugd/c2007e_305ca8f7ff5b4130b5fa6b0dee3fd4c3.pdf?index=true
    • http://puguvapalovuzub.rf.gd/amapiano_2019_dance_videos.pdf
    • https://s3.amazonaws.com/robumuduluwise/fogosekoratatofiramu.pdf
    • https://77483064-5892-4b52-b419-66e751946b77.filesusr.com/ugd/ef7b09_a24dcda8bf4c448b9870220d582c488d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/33c82f99-8586-4fd4-b313-a8bcb103a32e/70551044321.pdf
    • https://uploads.strikinglycdn.com/files/06a2017d-217b-4322-88aa-a82e8b345be0/liftmaster_elite_series_error_code_4-1.pdf
    • http://warufadul.rf.gd/binomische_formel_mit_brchen_rechner.pdf
    • https://7ae52be2-ba3c-41fb-8935-29281088223e.filesusr.com/ugd/affaa6_8958f806afd14c1db79b8ae599ccdfb3.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ecda.bin
830d4f23264553abab82de1fa7c7c61691187ecddd9f64b67ba3e0a1f4c2c43c
pdf-font-stream PDF embedded font (sfnt) at offset 0xECDA 4868 bytes
font_01_sfnt_off0000fd8c.bin
00caed55d453755c5fea3e07adda5677cace7b3e09642a844980beb67f994013
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD8C 10836 bytes