Malicious PDF — malware analysis report

Static analysis result for SHA-256 10cde886c23fa5ab…

MALICIOUS

PDF

71.0 KB Created: 2020-12-18 08:40:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: e79bd3584fd49fae2679799fcebc1321 SHA-1: 9261428e74c4a0a5b1d8db42251f49421b9ed4e5 SHA-256: 10cde886c23fa5ab800a17ca9067fe1763f956e7ff314dbfabb8f26d18a68a24
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF file was flagged by multiple heuristics and an ML classifier as malicious, with ClamAV identifying it as a phishing trojan. The file contains a large number of external links, many of which point to benign resources, but the primary external link identified is to 'trafftec.ru'. This suggests the document's purpose is to direct users to potentially malicious or deceptive websites, likely for phishing or SEO spam.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/123?utm_term=island+of+aeolia PDF link annotation
    • https://jubekufolofifi.weebly.com/uploads/1/3/4/5/134593927/c8c307.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/b4ece824-440a-4132-b712-e7caeb42f308/bunting_template_psd.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0c666116eb00e3c4b5099/t/5fc325981972c46e3c0535be/1606624665135/cats_pride_fresh_and_light_quick_action.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4b3fd613-a74b-4214-932f-d6d84882af2e/fijaf.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2bce0f8f-5fde-4572-badd-8424b6e55f66/45965449962.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fff7e7f0-061c-4d8e-8e00-8609e94b2a5e/78493260501.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/51fc4158-f179-4bfa-982a-76035aed30dc/67382829720.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc55cbca5bc066edfc3531b/t/5fcd0a20f94b6402b21e536a/1607272994993/zynn_hack_ios.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6365e49e-d8f0-45c6-95ba-2f20487853ad/xenemibifun.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc18bbd0b6b03258f3a1e10/t/5fc621c5cb3e0f5771215a79/1606820296410/armello_switch_local_multiplayer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b861bcb2-c938-4757-92c8-ad3d652ebaed/96292243997.pdfIn PDF document text
    • https://s3.amazonaws.com/tibitexil/32966138955.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3502fa4b-92cb-43ad-a9ea-e1a8036b4452/92147357844.pdfIn PDF document text
    • https://s3.amazonaws.com/lokijuronig/lezimufev.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d9ba.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD9BA 4740 bytes
SHA-256: 3841e373927420c74abb106e3f9b00663832ba3c2b8385586a911803ff25177d
font_01_sfnt_off0000e9ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE9EC 11364 bytes
SHA-256: 00f39d47c72d9adbe3326953674bc3c14bb4a20908444c711424533b1b54fa40