Malicious PDF — malware analysis report

Static analysis result for SHA-256 2bc95618b4e1e770…

MALICIOUS

PDF

89.0 KB Created: 2020-11-26 05:49:32 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-31
MD5: 23da00ceaf2bc1418c1f76e6be2ff094 SHA-1: d65293b9d75607d29b77ab420d117b8bca820845 SHA-256: 2bc95618b4e1e770f370ef4d0098dd712aa49bc5d2f3a56f5336e3794d51c985
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, many of which point to suspicious or unknown domains, indicating a link farm or redirector strategy. The heuristic firings confirm the presence of malicious redirector links and a link farm, suggesting the document's primary purpose is to drive traffic to malicious sites. While no scripts were extracted, the PDF structure and embedded links strongly suggest a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffmen.ru/wb?keyword=how%20to%20%20bluestacks%20without%20admin%20privileges In PDF document text
    • https://fogowedosetoz.weebly.com/uploads/1/3/4/7/134703805/bofomesox.pdfIn PDF document text
    • https://vorabatuzawudun.weebly.com/uploads/1/3/4/5/134582038/9504734.pdfIn PDF document text
    • https://wokepugef.weebly.com/uploads/1/3/4/9/134901336/bufojipavorupozune.pdfIn PDF document text
    • https://dusexitope.weebly.com/uploads/1/3/4/6/134646398/9944119.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/10bdd18e-a46b-46ae-8754-b41b6d1404c4/xafifubatag.pdfIn PDF document text
    • https://s3.amazonaws.com/faluzotixupi/the_vampire_lestat_free.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/930259a8-785d-4aa7-8c03-809dc7de87f3/bharat_acharya_coa_book.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5e939682-7557-49b0-8ce5-22d9b32ce323/jegug.pdfIn PDF document text
    • https://s3.amazonaws.com/gedimuta/100th_constitutional_amendment.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4657f7dd-0605-4d51-94c6-885aaf4a6ed4/suxizelawokadaxuraxojew.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f45f21d2-24ef-4dbd-ab0a-51e189bafd2a/jusopidesos.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/39425c79-6c53-460e-b98a-6d85b3b954af/64321795643.pdfIn PDF document text
    • https://s3.amazonaws.com/fadedosi/negolavevefebaj.pdfIn PDF document text
    • https://s3.amazonaws.com/fusidejebi/54285827714.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6a82078d-e25f-48db-92ff-552c9d81fab1/noveduwovutafegu.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011e1f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11E1F 5804 bytes
SHA-256: 37422d10190d33fcb48920f01d1e7ca21142408b6e42fbac4c8f4db38ed376d6
font_01_sfnt_off000131bf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x131BF 10816 bytes
SHA-256: c1488c0b44c415885486be7028fe975ec2a7ff7b6222bdb710322ce95761a4a3