Malicious PDF — malware analysis report

Static analysis result for SHA-256 30bb8255c41dbda8…

MALICIOUS

PDF

57.4 KB Created: 2020-12-18 00:34:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cf722eaa77c52fd2c2d8acd2fd34b2fc SHA-1: e566fc180fd204afbeca8a7260f2049ed6145a25 SHA-256: 30bb8255c41dbda89a50a96e3cc0050631bf3cf94c9fe36cbf02be9ad888e7aa
212 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple critical heuristics for containing malicious redirector links and a link farm. The primary malicious URL identified is likely used to redirect users to a phishing or malware site. While no scripts were explicitly extracted, the presence of numerous external links suggests an attempt to lure users to malicious content, aligning with spearphishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9711

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?utm_term=piedmont+public+schools+powerschool
    • https://mijekuwovosi.weebly.com/uploads/1/3/4/3/134321571/501721.pdf
    • https://xiworibamenu.weebly.com/uploads/1/3/4/7/134728691/7fe6bd478938e.pdf
    • https://lijasefevofik.weebly.com/uploads/1/3/4/8/134889997/5d9e9511.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbcf07e1491241adc445f65/1606217855172/umich_physics_240_textbook.pdf
    • https://s3.amazonaws.com/dadupawo/10699922418.pdf
    • https://static1.squarespace.com/static/5fc07d836b97992eb55a0df7/t/5fc0e2953570fb44d123be31/1606476439859/t7_power_max_cost.pdf
    • https://static1.squarespace.com/static/5fc37324df132613bbcddee0/t/5fc87c62b0f45b2a3d272254/1606974564047/syberia_2_game_length.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbd0b0368bfc5186169c63e/1606224645516/pro_forma_balance_sheet_using_percent_of_sales_method.pdf
    • https://s3.amazonaws.com/padoragog/39174313114.pdf
    • https://static1.squarespace.com/static/5fc0dd9b8ef7301f8b108504/t/5fcbc70a1ef6d1662ff7cf9a/1607190284637/48489018583.pdf
    • https://s3.amazonaws.com/lefemijip/20541506520.pdf
    • https://static1.squarespace.com/static/5fc06b148139af037642cc0d/t/5fc35deaa97599144e62e9f4/1606639082582/jakanosul.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b4c2.bin
39ec99a0a9d6ed90821c8489eecc57506658027c4fc81a8ef23a5794a82adf7a
pdf-font-stream PDF embedded font (sfnt) at offset 0xB4C2 5216 bytes
font_01_sfnt_off0000c656.bin
ab6c34a8bfd3fc872a8949097c5b36018cc0cb7e817bc0122685c91ade6b670a
pdf-font-stream PDF embedded font (sfnt) at offset 0xC656 10492 bytes