Malicious PDF — malware analysis report

Static analysis result for SHA-256 8494d45ac819c07a…

MALICIOUS

PDF

85.1 KB Created: 2021-03-22 22:32:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1023c313545ae664e03c4650569b193f SHA-1: 8ed4fa28c1a76338bb3f714d9006fe97b8f11091 SHA-256: 8494d45ac819c07ad1bdd1eaa381a439f3de24e9ec6826efd186ca8767df486f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics and a machine learning classifier as malicious, specifically as a phishing or trojan. It contains numerous external links, including one to 'pelibifir.ru', suggesting a phishing or link-farming attempt. The document body, though heavily obfuscated, appears to be a lure related to smartphone searches, aligning with phishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=best+smartphone+for+hearing+impaired+seniors
    • https://cdn-cms.f-static.net/uploads/4417815/normal_60194dcb094a2.pdf
    • https://visatedujapi.weebly.com/uploads/1/3/0/8/130814459/desusumenisise.pdf
    • https://cdn-cms.f-static.net/uploads/4381976/normal_5fd6e79e455ca.pdf
    • https://wozibasibif.weebly.com/uploads/1/3/4/8/134868806/084b8f.pdf
    • https://mugejonisisekof.weebly.com/uploads/1/3/1/4/131437633/151348.pdf
    • https://vegebawijinewer.weebly.com/uploads/1/3/2/7/132740558/27be0473001188.pdf
    • http://pivolirarorip.mypressonline.com/how_many_carbs_in_a_soft_chicken_taco.pdf
    • https://static.s123-cdn-static.com/uploads/4502819/normal_5fdd3869a339b.pdf
    • https://static.s123-cdn-static.com/uploads/4417805/normal_5fc9cc6ae3eae.pdf
    • https://jaluvipuruwagub.weebly.com/uploads/1/3/4/7/134734890/ef0228932b238.pdf
    • http://jedusajinud.mygamesonline.org/how_much_can_you_make_a_month_with_monat.pdf
    • http://neridofufuleteg.scienceontheweb.net/bagagexesilogename.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://9370005b-87d8-49d8-b27c-18dce193a2f1.filesusr.com/ugd/52ea04_0464cb847a5248c5913332383b1f53b4.pdf?index=true
    • https://dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com/ugd/0ebc1f_66da0b2e98dd433892b321794e609178.pdf?index=true
    • https://39c1d623-eccb-4af0-a86a-15328a2d61f9.filesusr.com/ugd/3cb6cb_a9b2d56ed9c14accb61275ded60de3a8.pdf?index=true
    • https://cd70d4e5-4a1a-4071-96d1-f2415ea5ece1.filesusr.com/ugd/7f46b5_6567c3b697504d60bbb873edd5c8c614.pdf?index=true
    • https://4a31e3f8-49e3-4331-b1a9-c0bb7a6b9dbc.filesusr.com/ugd/599f1c_d91a0e9d59e343ac9690a58be7e7cf4a.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010d08.bin
cd23218e546a035d25f08563d768b77ad0a92008ef7a33934c576d71c303e792
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D08 5472 bytes
font_01_sfnt_off00011f7d.bin
ba8703e328d3300ffaca413cb035e844598db8c6a8f0ed0052c0db0351fb5dc0
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F7D 11580 bytes