Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6e9306a94231ac9…

MALICIOUS

PDF

76.3 KB Created: 2021-05-19 20:21:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: eca0359b540d1a8f2c252d35b1b964cb SHA-1: a1982c21404aefbde2fe3f047e4f1ab2f1b77a32 SHA-256: d6e9306a94231ac922a17b0b3951a0f701947d42ec799ffaec3108fea12dfbde
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of external links, identified as a PDF SEO link farm. One of the primary links, 'https://pelibifir.ru/strik?utm_term=a+killer+among+us+filming+location', is flagged as malicious. ClamAV also detected this file as 'Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0', indicating a phishing or trojan payload. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=a+killer+among+us+filming+location
    • https://cdn-cms.f-static.net/uploads/4445869/normal_6054dbcea5f9e.pdf
    • https://static.s123-cdn-static.com/uploads/4466135/normal_5feec3f34ed49.pdf
    • https://cdn-cms.f-static.net/uploads/4491168/normal_6056d354c040d.pdf
    • https://cdn-cms.f-static.net/uploads/4416661/normal_5fe7965a8213a.pdf
    • https://tolopexe.weebly.com/uploads/1/3/1/0/131070113/ebe79182ee8b6.pdf
    • https://cdn-cms.f-static.net/uploads/4375080/normal_5fd918941f9cc.pdf
    • https://pakokapixufepu.weebly.com/uploads/1/3/4/6/134659136/3753844.pdf
    • https://static.s123-cdn-static.com/uploads/4417403/normal_6006486174057.pdf
    • https://cdn-cms.f-static.net/uploads/4378383/normal_604e98f164ecb.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/nonipesikiri/a_fathers_story_lionel_dahmer.pdf
    • https://s3.amazonaws.com/numegubowalonan/dakonugizalava.pdf
    • https://uploads.strikinglycdn.com/files/0f9443fa-f3a5-4a64-9d21-eeaf606d2e68/samsung_xpress_m2825dw_imaging_unit_replacement.pdf
    • https://s3.amazonaws.com/lebejos/lapipijoduxowobek.pdf
    • https://s3.amazonaws.com/pibajuwi/what_supermarkets_sell_gluten_free_products.pdf
    • https://s3.amazonaws.com/dowesitobuga/4th_grade_multiplication_coloring_worksheets.pdf
    • https://s3.amazonaws.com/pisik/verifone_vx520_manual_change_time.pdf
    • https://s3.amazonaws.com/nagev/neziguzumej.pdf
    • https://uploads.strikinglycdn.com/files/1ac0dfd9-e2c2-4c38-b24d-8a730ee95dee/rifiwe.pdf
    • https://s3.amazonaws.com/dejolavubukugeb/40094148484.pdf
    • https://uploads.strikinglycdn.com/files/57486db6-3349-4715-93b2-1bfc2b2c05bd/best_split_screen_survival_games_ps4.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed4d.bin
347bf9352eff5ba70370ca228d9d3b33827eedbcffda3ca7082f028aad44bc74
pdf-font-stream PDF embedded font (sfnt) at offset 0xED4D 5252 bytes
font_01_sfnt_off0000ff1e.bin
942909ae7971fa1957c45f8beef1df5d56e3e508d5d2596a977901e21f0c4e77
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF1E 10560 bytes