Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa1b3d07f69bc275…

MALICIOUS

PDF

81.1 KB Created: 2021-04-25 08:47:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: afccc82efd337fba9075b0ed4fea3ca7 SHA-1: 73bb1db14e10ff736fa7ac509de87cd2dd4e679d SHA-256: fa1b3d07f69bc2756b53bcdd026f6edbc8941afd009f59678f214c1cd237d88d
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by multiple heuristics and an ML classifier, specifically flagging it as a redirector link and a link farm. The embedded links, such as 'https://yafferge.ru/strik?utm_term=vista+128fbp+user+manual', likely lead to phishing sites or further malware downloads. The presence of numerous external links suggests an attempt to distribute malicious content or harvest user credentials.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=vista+128fbp+user+manual
    • https://cdn.sqhk.co/wepunajexiju/hphhXjj/happy_wheels_full_game_free_no_download.pdf
    • https://cdn-cms.f-static.net/uploads/4367914/normal_603fd37e95e7b.pdf
    • http://kutufirix.iblogger.org/renekifobegagudari.pdf
    • https://cdn.sqhk.co/vewukiziwemi/tgijgFk/60491821963.pdf
    • https://cdn.sqhk.co/rujiwujik/jahfAge/44047517056.pdf
    • https://cdn-cms.f-static.net/uploads/4421462/normal_60272a0ec654f.pdf
    • https://cdn.sqhk.co/bivuwusim/g20ihwo/peputufuzufakekumor.pdf
    • https://cdn.sqhk.co/ritasuxa/ciagihi/photoshop_free_online.pdf
    • https://cdn-cms.f-static.net/uploads/4480149/normal_606a571c95ac9.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://totawuvibewe.rf.gd/nubobefudunetunuge.pdf
    • http://gaxodusipif.epizy.com/ieee_integration_test_plan_template.pdf
    • https://s3.amazonaws.com/tobojelusiwi/49939813208.pdf
    • https://ede36962-9452-4451-b182-fa4236ba9bc6.filesusr.com/ugd/83b1b3_f8e941dd377e4c2f9a1d3bb54f239f2f.pdf?index=true
    • https://s3.amazonaws.com/wufujudisu/72087793141.pdf
    • https://s3.amazonaws.com/tetenifeme/autismo_que_es.pdf
    • https://01d67eed-50ba-4ccb-8f82-c1581f7ed07e.filesusr.com/ugd/e3325f_68b64cc7dca34f63bb9adb5b5cadf9db.pdf?index=true
    • http://donopopasuxek.epizy.com/rpp_biologi_sma_kelas_11.pdf
    • https://34ea5197-a9e9-4ba5-99bb-a7dd7aeba98b.filesusr.com/ugd/234f58_a919c4f0dfba4e2cb3ca74b1d5a31464.pdf?index=true
    • https://s3.amazonaws.com/tugumeb/kowujinate.pdf
    • https://s3.amazonaws.com/tixedujegibex/herpes_zoster_guideline_2019.pdf
    • https://s3.amazonaws.com/xezonijida/mepofalom.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000feba.bin
01361af48d26e2da4329ec142a8b7ed944687a6a00c17a4bf871f6d17459515f
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEBA 5528 bytes
font_01_sfnt_off00011174.bin
3976671a33d48359d70aaa99f7639f0e0212c4958b2ad46f33150128f9fbec08
pdf-font-stream PDF embedded font (sfnt) at offset 0x11174 10984 bytes