Malicious PDF — malware analysis report

Static analysis result for SHA-256 15ef2016a3a0a28b…

MALICIOUS

PDF

67.2 KB Created: 2020-12-18 00:46:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ba1e58fa7e26f14adf072dbd3a506bdf SHA-1: 580daeea4e3e3fea6a7d29bde63b1a496d240be1 SHA-256: 15ef2016a3a0a28b80a2314e8a4a6e73cc43fa256eaa335f401d18c6bfaaef41
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by ClamAV and an ML classifier. It contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic, with one prominent URL being https://traffset.ru/123?utm_term=jack+daniels+wood+chips. The document body is heavily obfuscated and appears to be generated content, likely intended to mask the malicious intent of directing users to potentially harmful external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/123?utm_term=jack+daniels+wood+chips
    • https://gugozakeku.weebly.com/uploads/1/3/4/5/134588211/3244400.pdf
    • https://megidawuxuta.weebly.com/uploads/1/3/4/7/134729580/7978150.pdf
    • https://wuwifure.weebly.com/uploads/1/3/4/6/134647121/duvamizixozamusotujo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/muvarelo/st_dorothy_glendora_bulletin.pdf
    • https://s3.amazonaws.com/zowejunef/the_celta_course_trainee_book.pdf
    • https://uploads.strikinglycdn.com/files/8955a8cf-042b-4cc3-96c2-c0266f1b9717/fezejapusubiva.pdf
    • https://uploads.strikinglycdn.com/files/09c8cbe4-8d46-4f55-bdb8-6799b0cde14f/93829152741.pdf
    • https://uploads.strikinglycdn.com/files/e5398d7c-fd73-44a2-bcdd-f0ce53f5a1fa/56532549020.pdf
    • https://s3.amazonaws.com/nepawigexa/tunes_movie_tv.pdf
    • https://uploads.strikinglycdn.com/files/cfc43e01-32ce-4998-a1eb-ff5950f06086/wopofixabazadob.pdf
    • https://s3.amazonaws.com/nagudo/drastic_emulator_apk_full.pdf
    • https://uploads.strikinglycdn.com/files/d3e10dc6-df56-45ad-9d4e-aeee2e2e6d07/29090088319.pdf
    • https://uploads.strikinglycdn.com/files/5ea3975e-6633-44d6-b736-3d9e00c3bc9e/9919733956.pdf
    • https://s3.amazonaws.com/wavunot/borat_movie_subtitles_english.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c663.bin
d1f6174e9d1fe2a3bb59106334d1925d5bd6bb017a04708a38a391318f6af2d4
pdf-font-stream PDF embedded font (sfnt) at offset 0xC663 5208 bytes
font_01_sfnt_off0000d830.bin
fc8a34d1f908f92544a0db01e36f33a82c07a50c3a88f4964b9ace673ad65851
pdf-font-stream PDF embedded font (sfnt) at offset 0xD830 11788 bytes