Malicious PDF — malware analysis report

Static analysis result for SHA-256 25847b40ecfe3b8a…

MALICIOUS

PDF

39.6 KB Created: 2020-11-05 16:40:36 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: 736ee578cc761457c7f6a89fa36fc2a7 SHA-1: 3a98fd858b9942fd8b99e63e37459be490b23e06 SHA-256: 25847b40ecfe3b8a4edcd958b2788b77543c1e8899a0f9a7ea2576bd9421e776
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a deceptive title and embeds multiple external links, including one to 'traffset.ru', suggesting a phishing or SEO spam campaign. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, many with numeric slugs, pointing towards an attempt to manipulate search engine results or drive traffic. While no scripts were explicitly extracted, the presence of embedded URLs and the ML classification strongly suggest malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/strik?keyword=how+to+see+correct+answers+on+canvas+quizzes PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4367617/normal_5f915c4a4ec4e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413109/normal_5fa19af6690f1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374853/normal_5f895a8da32b1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4384155/normal_5f92a95d4f8c4.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/kavalukato/41608878538.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0501/8409/3884/files/77741656479.pdfIn PDF document text
    • https://s3.amazonaws.com/debamijizozexo/52424985989.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0484/0652/8152/files/weston_public_schools_superintendent.pdfIn PDF document text
    • https://s3.amazonaws.com/sugosubexez/school_absent_notes.pdfIn PDF document text
    • https://s3.amazonaws.com/zupenafud/23984307759.pdfIn PDF document text
    • https://s3.amazonaws.com/dazemi/51062934141.pdfIn PDF document text
    • https://s3.amazonaws.com/zoromexemuzid/china_english_dictionary.pdfIn PDF document text
    • https://s3.amazonaws.com/mijedusovineti/gozisikuwuvukisavaserig.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005db3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5DB3 5052 bytes
SHA-256: 79eaff78d528e6512e83de7e02cd9598674eb6cfbb6d9a57642bfe5c4f714d49
font_01_sfnt_off00006f14.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6F14 10132 bytes
SHA-256: d6ca862a1e252e5455529d198d513857156b441723f4da760bc267b038910383