Malicious PDF — malware analysis report

Static analysis result for SHA-256 64fff1a0f66ae691…

MALICIOUS

PDF

74.1 KB Created: 2021-03-26 00:16:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a9a28865388f98161bc746ad58cdef7f SHA-1: 580f0553025d0470f71d67ac2bf540b9e985cc1c SHA-256: 64fff1a0f66ae691d735d141e752a5a1463cc8d5c6eab86267a1e1096f005d8c
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, with one suspicious URL pointing to 'pelibifir.ru'. ClamAV and ML heuristics also flagged the file as malicious, specifically as a phishing trojan. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic suggest the primary goal is to redirect users to malicious or deceptive content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/123?utm_term=diabetes+australia+treatment+guidelines
    • http://kopumiwabetare.66ghz.com/dark_mode_gmail_app_android.pdf
    • http://xujakebetutusu.22web.org/conversion_of_galvanometer_into_voltmeter_experiment.pdf
    • http://lozipazom.sportsontheweb.net/53018552230.pdf
    • http://zefujixa.mywebcommunity.org/assembler_language_with_assist_and_assist_in.pdf
    • http://dutarotanazosuv.medianewsonline.com/synchronous_motor_theory.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/13b27327-cafa-442c-8dfe-da639e830254/my_son_the_fanatic_movie_stream.pdf
    • https://b00f38ea-0d13-4519-ab0f-1253f0d03ca0.filesusr.com/ugd/289c5e_4a2a369c3ba44b6b9b64bbd741694c40.pdf?index=true
    • https://s3.amazonaws.com/jefobexapulow/18351448034.pdf
    • https://s3.amazonaws.com/gitipelut/birthday_card_cake_free.pdf
    • https://uploads.strikinglycdn.com/files/ea3ecd2b-3616-42ee-8636-7e8e2ae15f7f/slingbox_m1_wireless_setup.pdf
    • https://38e81cab-313f-462b-917d-d566bf782aa4.filesusr.com/ugd/36aba1_a924a3ccbc824b2088423e486a278f74.pdf?index=true
    • https://s3.amazonaws.com/tadevewuju/qradar_dsm_guide_7._3._1.pdf
    • https://s3.amazonaws.com/jivamubug/pedima.pdf
    • https://uploads.strikinglycdn.com/files/ac0d212c-1126-4a43-9fb6-632e1cdfbc26/how_can_i_track_my_american_eagle_order.pdf
    • http://gamanavaje.epizy.com/philip_kotler_marketing_management_free_download.pdf
    • https://59548cc9-d6a6-4b2e-bd73-2bfb7290c7b5.filesusr.com/ugd/3fd21f_2eca7557226f45c9806adf94c3df3c51.pdf?index=true
    • http://dimizisunope.epizy.com/multiplying_decimals_worksheets_grade_8.pdf
    • https://s3.amazonaws.com/rabewiruzitewa/shine_a_light_banners_song.pdf
    • https://2d2b1dae-c014-4902-97e6-c3f1d56915cd.filesusr.com/ugd/70e5f7_98629a2b28c049d0b18068fd6a905505.pdf?index=true
    • https://6478d21b-237c-41b5-add8-96d7b9819624.filesusr.com/ugd/c7ef1a_ca88153051f34889aac7065a4f3a58e4.pdf?index=true
    • https://db6d201d-bdff-4648-9982-d9cfaac7639e.filesusr.com/ugd/98857b_a88830497c5a4fabb742891f5e24d8b4.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e162.bin
b3c55c56f35de044e010c3201ba79de9628dec717424c783b791e9e0ac8453ac
pdf-font-stream PDF embedded font (sfnt) at offset 0xE162 5284 bytes
font_01_sfnt_off0000f343.bin
5e44924fda43899361c8d39345ff9877c080252ac90b6e5e7410a9795a30b87f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF343 12096 bytes