Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf2064182c513fb0…

MALICIOUS

PDF

74.0 KB Created: 2021-03-16 02:52:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c85ecd97b1414a33d2e0f31606cf280f SHA-1: dd590b124944effdea30bed3d04c62b0ef8c2924 SHA-256: bf2064182c513fb0aff65814ed3229389e44cf7b21b7bc8441fab0897c045f94
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF file was flagged by multiple heuristics as malicious, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. It contains a significant number of external links, indicating a link farm strategy to direct users to potentially malicious sites like 'pelibifir.ru' and 'magazinrf.xyz'. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/123?utm_term=barcode+scanner+android+google+play
    • http://magazinrf.xyz/rtgs_form_of_allahabad_bank_in_formatgzg3t.pdf
    • https://cdn.sqhk.co/zalivelo/hcpjbib/dosipexun.pdf
    • https://cdn.sqhk.co/nojedajoze/njjsYhi/detention_pond_maintenance_cost.pdf
    • https://cdn.sqhk.co/lovaxixifew/ijjLheP/view_booster_views_for_views_instagram.pdf
    • http://idealslimitaly.site/32069568532qo0e0.pdf
    • http://alteramaks.world/how_to_make_call_to_action_button_in_wordpresswexn8.pdf
    • http://pasendapp.online/summary_writing_exercises_with_answers_igcsewe17l.pdf
    • https://cdn.sqhk.co/rajexizeba/Iii2lhc/sabivalaxotajewemimepare.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c193e81f-4329-4033-91bb-dc0979e882e7/58128941096.pdf
    • https://e791dc30-71fd-4519-a75e-453748eb9c32.filesusr.com/ugd/8a5fcf_faa554e944e94ae5a4cdb066fd1832d2.pdf?index=true
    • https://636e06b3-920c-4898-b827-ef778bbbc101.filesusr.com/ugd/40512e_3b26de2185474029b9831056efdf86f5.pdf?index=true
    • https://b7eb3c74-9f10-4efd-a612-efb7ea03662f.filesusr.com/ugd/7198c1_351c21ce813049e6bf433335e49358d1.pdf?index=true
    • https://uploads.strikinglycdn.com/files/5da5dba3-b523-4286-8315-a3a2c1aa5624/how_to_program_a_chamberlain_garage_door_opener_953estd.pdf
    • https://s3.amazonaws.com/muvarelo/bram_stoker_dracula_film_1992.pdf
    • https://3465328d-eb21-4af5-a94e-b8fdacefaafa.filesusr.com/ugd/c63bf9_1cba72a422da438ba950640bbb217fe5.pdf?index=true
    • https://uploads.strikinglycdn.com/files/bacbc69e-a434-470d-ad09-7d8883d00061/cul_es_la_estructura_de_un_texto_narrativo.pdf
    • https://2e03c77f-99cc-4591-9807-54d8d49c9ce6.filesusr.com/ugd/759733_bdcb6df470904ec5a2cd3f0c6300938e.pdf?index=true
    • https://58552d80-c20c-4e4f-99b9-91bedbcc07a3.filesusr.com/ugd/c18496_ac07e96a27d74834bcc4b8081d80f6ca.pdf?index=true
    • https://s3.amazonaws.com/kubafezin/13170979300.pdf
    • https://ab60d57a-1f92-408f-9079-0b325776b613.filesusr.com/ugd/724fb5_4a13aa5c71a74f9eab580b519e6e61e0.pdf?index=true
    • https://uploads.strikinglycdn.com/files/fad1299b-9ae4-43a8-90fb-b456a7fa33b3/how_to_sweet_talk_your_lover.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e3b8.bin
d5f1625346337d81dd11a828c63293c82626a364dcb26fc9f7fe47d763eebfeb
pdf-font-stream PDF embedded font (sfnt) at offset 0xE3B8 5392 bytes
font_01_sfnt_off0000f623.bin
1a2d96c2c9bee9f8fd2fd899b12584a3bdeda132ed94865e594a987b8e2dad99
pdf-font-stream PDF embedded font (sfnt) at offset 0xF623 10828 bytes