Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b5dedd388eef89b…

MALICIOUS

PDF

61.7 KB Created: 2020-12-21 12:55:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b8c8ab92571f4954782444e8777fa8b9 SHA-1: 026f748514c0b4855ea746fa40c57b5362b144c7 SHA-256: 2b5dedd388eef89b15d810ff70ec61ea40468f80512abf49ed7602530d59ff75
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics, including a critical finding for a PDF link farm containing numerous external links. The ML classifier and ClamAV detection strongly indicate malicious intent. The embedded URLs suggest the document is designed to redirect users to potentially harmful websites, possibly as part of a phishing or SEO manipulation scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/123?utm_term=basic+cooking+terms+answers
    • https://jafobepajimo.weebly.com/uploads/1/3/4/8/134881918/mixikumas-finapejogalose-vunus.pdf
    • https://mabanopovofed.weebly.com/uploads/1/3/1/4/131453130/9183887.pdf
    • https://cdn-cms.f-static.net/uploads/4472486/normal_5fad69eb4c35f.pdf
    • https://cdn-cms.f-static.net/uploads/4485826/normal_5fb51cfa5de5a.pdf
    • https://static.s123-cdn-static.com/uploads/4454545/normal_5fc6b085eb53d.pdf
    • https://cdn-cms.f-static.net/uploads/4366377/normal_5f8712ee99045.pdf
    • https://cdn-cms.f-static.net/uploads/4426677/normal_5f9f2b2cae193.pdf
    • https://degezumibupupek.weebly.com/uploads/1/3/4/8/134862322/xikameminusufawozu.pdf
    • https://buvupoxiku.weebly.com/uploads/1/3/4/3/134329971/1da5c6.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/35d5bc12-2639-4779-aabe-45ffa8d4517d/razitedume.pdf
    • https://uploads.strikinglycdn.com/files/130ca969-0be6-43de-9e78-5fc9b0f76d2d/unit_13_ps_vita.pdf
    • https://uploads.strikinglycdn.com/files/2593170c-1fc4-464d-9580-b16003cb8454/64673552303.pdf
    • https://uploads.strikinglycdn.com/files/61d39920-b65c-4196-bfc4-9e4dd47f0b09/85362134948.pdf
    • https://uploads.strikinglycdn.com/files/5148dac2-126f-44ac-8629-b1d294f16e7b/48892619240.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b697.bin
ff88e15219c5321b43bb521b831bacdaa60cb99c6c1dc207ef46f2ca7544f011
pdf-font-stream PDF embedded font (sfnt) at offset 0xB697 5292 bytes
font_01_sfnt_off0000c898.bin
67442a8dc1ee5fa1328f463ff9d6647387aac2bb3824889585d8c8d90c3e4101
pdf-font-stream PDF embedded font (sfnt) at offset 0xC898 9848 bytes