Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a76fb8918042d7d…

MALICIOUS

PDF

69.6 KB Created: 2020-11-17 17:49:39 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 122211e2107b8ed99d6e7ba27a929129 SHA-1: e451241d22a0013d40211bd848fba662dc11b267 SHA-256: 2a76fb8918042d7ddf01ccd50ebfe8a4d8cdb1b6d9e1ed0614601c304c5df53e
212 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs, with a critical heuristic firing indicating it links to known malicious redirector infrastructure. The document body, though heavily obfuscated, appears to contain text related to '80s music download sites', suggesting a lure. The presence of numerous external PDF links further supports the 'PDF_SEO_LINK_FARM' heuristic, indicating a likely attempt to manipulate search engine results or distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9704

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?utm_term=best+80s+music+download+sites
    • https://lififotepul.weebly.com/uploads/1/3/4/3/134339298/zalapatizobozure.pdf
    • https://cdn-cms.f-static.net/uploads/4416810/normal_5f9f8dd417ee4.pdf
    • https://cdn-cms.f-static.net/uploads/4383692/normal_5f934e6231fd4.pdf
    • https://cdn-cms.f-static.net/uploads/4367941/normal_5fad88be0b02b.pdf
    • https://cdn-cms.f-static.net/uploads/4366304/normal_5f9993a13d1e8.pdf
    • https://cdn-cms.f-static.net/uploads/4424630/normal_5f999f47ca66a.pdf
    • https://cdn-cms.f-static.net/uploads/4366661/normal_5f9a3c735f15e.pdf
    • https://cdn-cms.f-static.net/uploads/4379355/normal_5fabb853801ba.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/b1a7884f-160f-4539-aa89-0080c7b2042c/67147184365.pdf
    • https://s3.amazonaws.com/buxoparadazegu/wumadiwijasikutuzumoled.pdf
    • https://uploads.strikinglycdn.com/files/8005d9c4-1969-436a-a2d3-7c055f3c2792/laserdisc_price_guide.pdf
    • https://s3.amazonaws.com/pozokimepe/team_kirby_clash_deluxe_guide.pdf
    • https://s3.amazonaws.com/sajatofubote/buperi.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e246.bin
b35abcb8bc9916459ab4bc5fbe037e92fa6c61e5350babb9600fcbe90d8c5641
pdf-font-stream PDF embedded font (sfnt) at offset 0xE246 5464 bytes
font_01_sfnt_off0000f4db.bin
73fcbf2ef8887cfed1148792b5d1bfede3a21c45b0f16b038b012297a9a5e94d
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4DB 10520 bytes