Malicious PDF — malware analysis report

Static analysis result for SHA-256 1bd10e93c2bcb27a…

MALICIOUS

PDF

61.1 KB Created: 2020-11-23 06:33:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 933f34a99977b402139a81d35c58764b SHA-1: 99d21b6bb72d705c7bbf6a09e4a4b2fd9b36f3ff SHA-256: 1bd10e93c2bcb27a9af78aad0486d886cd789a8c74913bf25f8b477c9b09a187
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains heuristics indicating it is a link farm and has been flagged by a machine learning classifier and ClamAV as malicious. The document body, though partially corrupted, suggests a lure related to 'Bluetooth software for windows 10 free'. The presence of external URIs, particularly the one pointing to 'trafftec.ru', indicates a likely phishing or scam attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7544

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/aws?utm_term=bluetooth+software+for+windows+10+free
    • https://cdn-cms.f-static.net/uploads/4405437/normal_5fbab3e5a0f7a.pdf
    • https://cdn-cms.f-static.net/uploads/4416512/normal_5fab2d106af1e.pdf
    • https://kesevaze.weebly.com/uploads/1/3/1/3/131383297/jilogiwosokuji.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/48e02919-c5dd-4d02-9e79-6212d1f671f7/fozugerinepoxejani.pdf
    • https://uploads.strikinglycdn.com/files/b69d35b8-3ebd-4e32-8750-d320a5219902/drake_ft_21_savage_mp3.pdf
    • https://uploads.strikinglycdn.com/files/f03b907d-6bbc-4025-9774-664a477ee8b7/rasetabenowofigisinube.pdf
    • https://uploads.strikinglycdn.com/files/122d784b-a4cb-41b8-a6b5-70791412f485/aws_certified_solutions_architect_study_guide_associate.pdf
    • https://uploads.strikinglycdn.com/files/ff06092c-5450-41b2-b282-cd0caea76c22/79823784940.pdf
    • https://uploads.strikinglycdn.com/files/f6bbfebe-e97e-40e3-a797-f194aa0a8a1c/solid_copper_45_acp_bullets.pdf
    • https://s3.amazonaws.com/fosagobomap/blue_fusion_1000_plush_pillow_top_mattress.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d67b.bin
aafc5e16a75fc654b2a2f928b9c1afd01a5e0611f3bdd4781ba6f5c080f2379a
pdf-font-stream PDF embedded font (sfnt) at offset 0xD67B 5332 bytes