Malicious PDF — malware analysis report

Static analysis result for SHA-256 319a53f9c7bffe23…

MALICIOUS

PDF

75.9 KB Created: 2020-12-20 11:51:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ddafa823b1717fb083d015aaf5d363f2 SHA-1: 1e13ac361fdf692922c7eb9d8e17bc39254b34ba SHA-256: 319a53f9c7bffe239110dae274ec0e840003232d7e628a1fbe2afa4b785ea4ff
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic firing for a malicious redirector link pointing to 'https://gettraff.ru/strik?utm_term=html+objective+questions+and+answers+pdf+free+download'. The document body, though heavily obfuscated, suggests a lure related to downloading HTML objective questions and answers. The ML classifier and ClamAV also flagged this PDF as malicious, indicating a phishing or trojanized document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/strik?utm_term=html+objective+questions+and+answers+pdf+free+download
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/ed69a0c6-ea43-44b7-a6e6-832b848675b9/16972558081.pdf
    • https://uploads.strikinglycdn.com/files/1864765a-783c-4ef3-88e8-dc7cff35f118/4537303787.pdf
    • https://uploads.strikinglycdn.com/files/4c6557af-269d-4df4-afd8-1d2010c20e7c/ap_biology_mitosis_and_meiosis_lab_answers.pdf
    • https://uploads.strikinglycdn.com/files/ddb0d58b-22a5-4b99-a1d6-bff9d5c7a742/sigijidaguwogokegapujofuj.pdf
    • https://uploads.strikinglycdn.com/files/6a0ff685-e261-4ed5-b5bc-098b34b6f533/think_like_a_billionaire_become_a_bi.pdf
    • https://uploads.strikinglycdn.com/files/4ac1114d-3f57-478f-bfe5-2a01da0fb502/sejuxekonuvu.pdf
    • https://s3.amazonaws.com/tutasujal/birthday_cake_name_editor.pdf
    • https://uploads.strikinglycdn.com/files/b384dc83-5cd3-4872-a481-5c63f2d499ed/sophia_lillis_real_height.pdf
    • https://uploads.strikinglycdn.com/files/8ffecfd0-e475-4e19-8e41-0ca450d53de5/pedatumokaruvete.pdf
    • https://uploads.strikinglycdn.com/files/7556a5d5-aa90-40d4-b4be-c1851ca282ff/bitcoin_miner_free_apk.pdf
    • https://s3.amazonaws.com/dorobukasawituw/68137120243.pdf
    • https://s3.amazonaws.com/forupokisip/consumer_reports_canada_electric_vehicles.pdf
    • https://uploads.strikinglycdn.com/files/f16d7a65-eb3c-4b87-9b4c-17bb2be0e5a1/xegamitiwazejodigebufito.pdf
    • https://s3.amazonaws.com/xarojapi/quantitative_approach_to_management.pdf
    • https://uploads.strikinglycdn.com/files/404b41cc-3dc7-4172-80c5-f4c75b453e96/asphalt_8_mod_apk_unlimited_money_and_tokens_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8a8.bin
baef57f03539f76e54eef8f3e7acf48c8a1ed035ba7915caa4ecbc9ce16c16bd
pdf-font-stream PDF embedded font (sfnt) at offset 0xE8A8 5756 bytes
font_01_sfnt_off0000fc3b.bin
97ef0cf395ba8abac2cb42852de82dceb6c0570d50cfc0e1210856a202668b26
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC3B 11324 bytes