Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a55b778d03f7ea0…

MALICIOUS

PDF

79.7 KB Created: 2021-03-30 15:09:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-20
MD5: 59dfe7eca394984c118caad6fb1eee8d SHA-1: b282e5641fc9df73ce590f9e8972844bfdd0a749 SHA-256: 7a55b778d03f7ea0db3ee94481cfe886277cf862c2d7a4f0a641da517bd1a017
134 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains numerous external URIs, including one pointing to 'pelibifir.ru', which is likely part of a link farm designed to redirect users. The presence of a 'download button' heuristic further supports the phishing lure attack pattern. The document body, though heavily obfuscated, contains references to 'wkhtmltopdf' and a date, suggesting it was generated programmatically to appear as a legitimate download link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=spoken+english+through+telugu+books+free+download PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4470833/normal_602fdb1d6271e.pdfIn PDF document text
    • https://cdn.sqhk.co/sonometa/dmPqgfw/easy_launcher_for_seniors.pdfIn PDF document text
    • https://cdn.sqhk.co/vilubofi/jjhmheW/battle_angel_alita_mars_chronicle_online.pdfIn PDF document text
    • http://copyrighthelpptteam.com/dajemrrd2p.pdfIn PDF document text
    • https://cdn.sqhk.co/lojibuwe/xia4ghb/65683251690.pdfIn PDF document text
    • http://converstarget.ru/simple_deposit_agreement_template_ukq794b.pdfIn PDF document text
    • https://cdn.sqhk.co/pesamelez/hhhdhbS/80173546860.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4467979/normal_5fefbc3d61694.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4419857/normal_5feb5c0fd04cd.pdfIn PDF document text
    • http://esagafow.fun/fuvuginoxul1w5k.pdfIn PDF document text
    • https://cdn.sqhk.co/rapawaferew/cNhfZib/dialectic_of_enlightenment.pdfIn PDF document text
    • http://netewe9.xyz/flip_phones_for_sale_at_walmartn8slz.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4495531/normal_5ffe5040e6426.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/b4300c88-20b5-47ba-b56b-40451cd05456/loxegidobojidutitivuful.pdfIn PDF document text
    • https://ddf64d59-5240-4154-9987-17dfc28e22c7.filesusr.com/ugd/cec570_7294cbbabd48494d932cec315dd132b0.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/f49bd854-3af3-4009-8e32-d9437f8476db/jupyter_notebook_install_python_3.5.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7963ca39-2109-47bf-ae45-3df658a0d604/how_to_reset_smart_socket.pdfIn PDF document text
    • https://e905e09d-7ddd-4aab-833c-73500e817873.filesusr.com/ugd/f4c08b_9ad15ad3a56c4237b62225bcfeb29fb1.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/pewebopufupe/spacex_falcon_heavy_launch_video.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fe1b1835-7169-4b9a-879c-846584374ff4/xosujulakadedaparivegirul.pdfIn PDF document text
    • https://4bc473c2-84d0-4913-8b4e-281bf44fba2e.filesusr.com/ugd/a25dbd_4c38cc01dd494af9a1f2974fa928590a.pdf?index=trueIn PDF document text
    • https://7ec9ed57-df89-401a-953b-45744c150cee.filesusr.com/ugd/6e3131_593d14727fcd4312b4c306f2d3e86740.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/viboxikuz/how_to_align_liftmaster_garage_door_sensors.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9b3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE9B3 5584 bytes
SHA-256: ced2cbfef83d3e13f6c138c9721895e870485d4f3ab9e277db3aada74449e008
font_01_sfnt_off0000fcae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFCAE 11112 bytes
SHA-256: fd41c5ba46e115b104fc1859285e1ec20bc911ae6c9aea59d885d5a7ea3b9091
font_02_sfnt_off000122a5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x122A5 4324 bytes
SHA-256: cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34