Malicious PDF — malware analysis report

Static analysis result for SHA-256 225dd98cf093c09d…

MALICIOUS

PDF

67.6 KB Created: 2020-12-03 15:44:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 264b60dec99e0fda86233be14c14ff78 SHA-1: 5764d7404a18597397e2aba71bce7df1322f9233 SHA-256: 225dd98cf093c09d7ec8a99c419cdb61be4085b0743df5302e88c0c2c4776920
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic firing for a 'PDF_SEO_LINK_FARM' which indicates a large number of external links, many of which are likely malicious. One of the primary external URIs points to 'traffset.ru', a known malicious domain. The document body, though heavily obfuscated, suggests a lure related to 'Bible study apps for android phones' to entice users to click on the malicious links. The ClamAV detection further confirms the malicious nature of the file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7962

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/aws?utm_term=bible+study+apps+for+android+phones
    • https://cdn-cms.f-static.net/uploads/4371786/normal_5f9f2c749b381.pdf
    • https://cdn-cms.f-static.net/uploads/4410459/normal_5fc0bb504caba.pdf
    • https://kegazesawatodo.weebly.com/uploads/1/3/4/3/134378031/zimaje.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/73dd7d41-4142-402b-91f9-0653293e458f/elf_on_the_shelf_return_letter_free_printable.pdf
    • https://uploads.strikinglycdn.com/files/a3bb639f-dbf1-4b93-9e19-ba21ad3eae2a/59795819988.pdf
    • https://uploads.strikinglycdn.com/files/cbcd21da-954c-4887-8007-607f06278f01/bitcoin_miner_apk_android.pdf
    • https://static1.squarespace.com/static/5fc27e6e3398ff7515381371/t/5fc8eaa30b7183349bd6949f/1607002789578/freak_show_sound_id.pdf
    • https://static1.squarespace.com/static/5fc1a551b8467722f1d988e0/t/5fc5c3c8fa04221c71e809fe/1606796233134/wobuxakalebeso.pdf
    • https://uploads.strikinglycdn.com/files/9744d73b-2688-422e-b7b5-010f41c0dea7/12151692915.pdf
    • https://s3.amazonaws.com/henghuili-files2/libros_de_canciones_para_guitarra_gratis.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f44e.bin
4da316af402d27d92ead87b1be0d558c466c064568f6167808c0fe2bf15dbceb
pdf-font-stream PDF embedded font (sfnt) at offset 0xF44E 5300 bytes