Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6d2468a47fb3d62…

MALICIOUS

PDF

87.6 KB Created: 2021-05-03 06:28:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 43c9b3fe6b546249007d30b674c85ef4 SHA-1: 2924d3429268ff58ffc747d910af902e724abc11 SHA-256: c6d2468a47fb3d62e2a05c6540853d6bc5279d6d7a1c5c1f18e0a4f48e98fc4d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by multiple heuristics, including ClamAV and an ML classifier, and contains a large number of external links. The primary malicious URL, https://pelibifir.ru/strik?utm_term=ti+ba+ii+plus+professional+vs+ti+ba+ii+plus, suggests a phishing or malware distribution attempt. The document body, though heavily obfuscated, contains metadata related to 'wkhtmltopdf' and a date, indicating it was likely generated programmatically to host these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=ti+ba+ii+plus+professional+vs+ti+ba+ii+plus
    • https://fiziwiminika.weebly.com/uploads/1/3/4/6/134686918/bogababaxeva.pdf
    • https://cdn.sqhk.co/defisepeniba/PngfVdF/ragdoll_soldiers_the_combat_warriors_game_schedule.pdf
    • https://xisidugaboker.weebly.com/uploads/1/3/4/4/134436298/6849055.pdf
    • https://cdn.sqhk.co/pusuvizodez/epsENk9/tofofogare.pdf
    • https://cdn.sqhk.co/ravusigi/gdhhVb6/35949482494.pdf
    • https://bezamefiparafu.weebly.com/uploads/1/3/4/6/134665790/xabufesozes_wodigemirule_lusopib.pdf
    • https://cdn.sqhk.co/feduvefas/gcQbN2b/plantar_wart_or_corn_pictures.pdf
    • https://cdn.sqhk.co/tezasevimab/Bogdvhb/boss_battle_games_unblocked.pdf
    • https://zenozuniwilifa.weebly.com/uploads/1/3/4/1/134131556/latelopupewogabu.pdf
    • https://cdn.sqhk.co/fuvebopeweb/D8hjihi/the_gunner_stickman_weapon_hero_mod.pdf
    • https://xisofigutuf.weebly.com/uploads/1/3/0/7/130740477/6072386.pdf
    • https://cdn.sqhk.co/soziwariru/NwjeOjG/jazanuv.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/d18925d0-4ce3-4194-bc0f-66464898eef7/muwoga.pdf
    • https://uploads.strikinglycdn.com/files/a1c9556f-7efe-44fd-bf17-103b17039b02/jhumpa_lahiri_a_temporary_matter.pdf
    • https://de461234-8179-4892-b46d-67dc01ae00af.filesusr.com/ugd/69bbc5_d0c90cb12a914c6bbad3392c78bc25ba.pdf?index=true
    • https://4b5f4e46-8b81-4257-bf39-61fc08ba57b0.filesusr.com/ugd/7ea8bb_6395b69567a64579b32571c03be789ae.pdf?index=true
    • https://s3.amazonaws.com/bubodeliza/cross_flow_heat_exchanger_experiment_lab_report.pdf
    • https://uploads.strikinglycdn.com/files/2ad135b8-5fe2-47e2-a351-a81367873375/95599539010.pdf
    • https://s3.amazonaws.com/zifilobesumafi/fofojoripupatolobemebotur.pdf
    • https://e4fb9bf1-a3d6-4767-9bf2-2a1021e5dc09.filesusr.com/ugd/53cfc7_19a012154c58455ab10b2e7e9e414d54.pdf?index=true
    • https://uploads.strikinglycdn.com/files/4cbbb171-9ef0-4aa4-a8a2-4a9b607011dc/diy_ar-15_mag_coupler.pdf
    • https://c18d7360-3707-4bf1-9d6f-52ba7510fa17.filesusr.com/ugd/76cb06_63d3c262ace14ceab6b3a3bac43889dc.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f476.bin
159acedad9d978cae9bfe038eaad3407835a89dc283836efc716e81efcbeccd8
pdf-font-stream PDF embedded font (sfnt) at offset 0xF476 5044 bytes
font_01_sfnt_off000105af.bin
269104fe344301075bb373450fba23043a1abe236c48cc43b2b4bfb24336e162
pdf-font-stream PDF embedded font (sfnt) at offset 0x105AF 16156 bytes
font_02_sfnt_off00013829.bin
bf8f9ece8d9d74ce2d7a98a07ee1bb8f4056faf702b3b1702118181e85f1b939
pdf-font-stream PDF embedded font (sfnt) at offset 0x13829 16312 bytes