Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e58bcc5a59bf629…

MALICIOUS

PDF

74.9 KB Created: 2020-11-11 12:10:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: da5e188d7252b1b73b407bdd026b469c SHA-1: 141ef242749253b759ee5db2965c7d8ef5337d20 SHA-256: 0e58bcc5a59bf6298c30d87abbaf9739cb3497b7fe188a5d791dcc930be9b13c
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links that redirect to malicious infrastructure, specifically a URL related to 'minecraft pocket edition 14.0 apk'. This indicates a phishing or scam attempt designed to trick users into visiting a compromised site. The ML classifier and ClamAV detection strongly support the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/123?keyword=minecraft+pocket+edition+14.0+apk
    • https://cdn-cms.f-static.net/uploads/4455894/normal_5fa3176a2806a.pdf
    • https://cdn-cms.f-static.net/uploads/4373008/normal_5f93250a5dae7.pdf
    • https://cdn-cms.f-static.net/uploads/4455396/normal_5fa99d5517ff6.pdf
    • https://cdn-cms.f-static.net/uploads/4383452/normal_5f8e69fe31be7.pdf
    • https://fawugidizewok.weebly.com/uploads/1/3/4/0/134012544/pivizegatuj_rozasotu_kafaduvozexowiv.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/nitajosasa/let_it_snow_by_david_sedaris_thoughts.pdf
    • https://uploads.strikinglycdn.com/files/f191fb5f-cf69-40b6-8de6-cd76d8340a0a/98895689390.pdf
    • https://uploads.strikinglycdn.com/files/83f9b2a4-ae1d-403b-8d83-7ab7aca145fa/58158270279.pdf
    • https://uploads.strikinglycdn.com/files/27fd4571-5128-4e73-a072-b926cb31e53b/92605561962.pdf
    • https://uploads.strikinglycdn.com/files/2ebb6fb8-0a6d-4864-b8dd-e50318a61cc5/gifiridid.pdf
    • https://uploads.strikinglycdn.com/files/8328460e-992c-499e-84fd-c30ae48585a5/86045147640.pdf
    • https://s3.amazonaws.com/zabevog/my_galaxy_app_download.pdf
    • https://uploads.strikinglycdn.com/files/c9891d7b-ed18-4046-8d14-0e91ac41e64e/89411696139.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c456.bin
a909daaa3493d89245c3b5912e61d1d24aca938a67d855e7471322ab1c3114bf
pdf-font-stream PDF embedded font (sfnt) at offset 0xC456 2920 bytes
font_01_sfnt_off0000ceaf.bin
6cead73592fc112b334eb61e19abcfb97b14b6a0a5b59f8900fe7e376828e457
pdf-font-stream PDF embedded font (sfnt) at offset 0xCEAF 5320 bytes
font_02_sfnt_off0000e0f5.bin
c1a5c890f6fd45a2d6c19887a59227d9ee99829fcd6690618b4614d754040e0f
pdf-font-stream PDF embedded font (sfnt) at offset 0xE0F5 10616 bytes
font_03_sfnt_off00010391.bin
0c9ea411b363b9e3685beb7ff9a44f52508e7bcff9d28012656eab9674dbb078
pdf-font-stream PDF embedded font (sfnt) at offset 0x10391 16920 bytes