Malicious PDF — malware analysis report

Static analysis result for SHA-256 53d796526de6d989…

MALICIOUS

PDF

68.0 KB Created: 2020-11-18 04:10:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 822f0fcd8c8f2aca0ae91ada16a7bbd0 SHA-1: b9f30eb80acae826dc6d5b1f334e65d83b93ed6f SHA-256: 53d796526de6d989b13f3363afce2a9d4e79ec755cb94724566f7301c0962600
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by multiple heuristics and a machine learning classifier, specifically flagged as a phishing trojan. It contains numerous external links, including one to 'traffnew.ru', suggesting an attempt to redirect users to malicious sites. The presence of embedded links and the overall structure indicate a likely phishing or malware distribution campaign, potentially using the 'dinosaur birthday cake' theme as a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/123?utm_term=dinosaur+birthday+cake
    • https://cdn-cms.f-static.net/uploads/4416661/normal_5f9922511f4c2.pdf
    • https://rusekawavupor.weebly.com/uploads/1/3/4/0/134096427/nivepatobalenupafage.pdf
    • https://cdn-cms.f-static.net/uploads/4415530/normal_5fabeaf2bf2a6.pdf
    • https://cdn-cms.f-static.net/uploads/4454575/normal_5fa8fd64e774d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/zukukelejurotef/fb_audience_blaster_serial_key.pdf
    • https://uploads.strikinglycdn.com/files/c4fb24b3-38d1-49d8-82bf-df6d1a9eb14a/jakur.pdf
    • https://s3.amazonaws.com/wenobagupexekap/13922352103.pdf
    • https://uploads.strikinglycdn.com/files/be4d4d5f-9861-447f-b3a2-da8836dc59f9/wokuvopojirawixupupoxa.pdf
    • https://uploads.strikinglycdn.com/files/15c6902a-8e65-414c-b47a-5acfcb147ddb/civilization_5_brave_new_world_manual.pdf
    • https://uploads.strikinglycdn.com/files/af660c51-40a2-46d7-9f88-7bc48ea39745/21000518466.pdf
    • https://s3.amazonaws.com/vutame/63473165409.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cf44.bin
873438b127ef53b0e8a56e489d264f671cdd5f5310a7cb69e997d26db8ce3238
pdf-font-stream PDF embedded font (sfnt) at offset 0xCF44 5300 bytes
font_01_sfnt_off0000e14d.bin
f716708793ef320c9290e84057292354817d088810a2eb01c3a1f9cfba18931c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE14D 10008 bytes