Malicious PDF — malware analysis report

Static analysis result for SHA-256 1573476e7e7bd2b0…

MALICIOUS

PDF

75.1 KB Created: 2020-11-18 03:43:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0b319bd1ef69080840fc0a620d0ab23e SHA-1: 52781bdb06ff00a4e86c1336f884aeeefa1cae48 SHA-256: 1573476e7e7bd2b02659ef605dcf878fe78dbb1b8ed7e13aa5ac198740e9ee1f
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous embedded links, with at least one pointing to known malicious redirector infrastructure. The heuristic firings indicate that this PDF is designed as a link farm, likely to distribute malware or conduct phishing. The ML classifier and ClamAV detection strongly support its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/aws?utm_term=ipcc+assessment+report+1
    • https://cdn-cms.f-static.net/uploads/4369486/normal_5f880eb68e064.pdf
    • https://cdn-cms.f-static.net/uploads/4419642/normal_5fa26a9e3b5c9.pdf
    • https://xelefivaj.weebly.com/uploads/1/3/4/2/134234850/kukufoxoruxipija.pdf
    • https://cdn-cms.f-static.net/uploads/4452377/normal_5fb47172d5c50.pdf
    • https://cdn-cms.f-static.net/uploads/4462362/normal_5faafcdd32e2e.pdf
    • https://cdn-cms.f-static.net/uploads/4366317/normal_5faaa6d0b6b4e.pdf
    • https://cdn-cms.f-static.net/uploads/4365562/normal_5f9fad0b8a979.pdf
    • https://cdn-cms.f-static.net/uploads/4367300/normal_5fa92cfce2abc.pdf
    • https://cdn-cms.f-static.net/uploads/4384461/normal_5f8e1add1cf20.pdf
    • https://cdn-cms.f-static.net/uploads/4499023/normal_5fb258e8d6d0c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/rovikibixu/advanced_vocabulary_quiz.pdf
    • https://uploads.strikinglycdn.com/files/e62a8e76-f47f-44a2-bc7e-12d6994ae6a6/77995338417.pdf
    • https://uploads.strikinglycdn.com/files/829d2d98-e334-480e-b9b3-50ccc9a3e512/32474040223.pdf
    • https://uploads.strikinglycdn.com/files/2987fa35-e95a-4d1f-99e7-facdf014a9ea/pexujafiwotodejami.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e936.bin
d2b4c7e33ab9253f1143d39c30a283a13f04601dfe9f0b92d6d5031fc30b27f6
pdf-font-stream PDF embedded font (sfnt) at offset 0xE936 5036 bytes
font_01_sfnt_off0000fa41.bin
ce1f8faa032d4f0d55e8d8c83efbc8ddbbe2b60a005046787dd49f4bac5d40b4
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA41 11136 bytes