Malicious PDF — malware analysis report

Static analysis result for SHA-256 5850b13e56005a3c…

MALICIOUS

PDF

33.6 KB Created: 2020-10-09 01:16:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-23
MD5: 2c31a9c06cac18c2fae3d61d00d6febe SHA-1: 5db4705f33083d4774d7070f95e351916513461f SHA-256: 5850b13e56005a3c0793f553aedc0e87f112801e071feb2e7d7d643980e7f43b
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document contains a mass of external links, including a known malicious redirector. The document body, though obfuscated, contains the URL 'https://gettraff.ru/strik?keyword=editable+pdf+creator', suggesting a lure to a malicious site disguised as a PDF creator. The presence of numerous links to external PDFs and the ML classifier's high confidence indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/strik?keyword=editable+pdf+creator In PDF document text
    • http://files.yonelfashion.com/uploads/1/3/0/7/130776148/7273542.pdfIn PDF document text
    • http://jelusuba.jcovercomersministries.net/uploads/1/3/1/4/131438562/daligudebesexim-fuwatuk.pdfIn PDF document text
    • http://files.catryanmedium.com/uploads/1/3/2/6/132695636/kubotaxowiwi_jukizowarim_timoxob.pdfIn PDF document text
    • http://mijar.stfranciscentre.net/uploads/1/3/0/8/130814328/bozixabos_rofufojasipu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/53e31ef1-af42-4b02-a7ce-4b82e4a8cf1c/16916029349.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d677f213-4116-4814-85c1-d229e83123a3/makigodavuburelapinul.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f026916f-c1c3-45de-893c-2b5a964410db/doradifa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/906c6337-61aa-4a56-8b6b-576f7df31a68/zisazewadega.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9ef357ee-e8de-45f3-8fe1-12992fac1213/7747274936.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/02e6b4c5-3869-4c02-9d37-f739a743a3cf/82321969811.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/090ad5a5-bb45-4279-89b1-e43a23c6ef38/wivopibaguvegifubetugaf.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f30532f6-d616-4119-9596-c85d62588013/8130037324.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/82d5bc9a-dfec-4b88-bb7e-733b1d0f5e9c/99042956039.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000048b9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x48B9 5068 bytes
SHA-256: 6cfac06948648da29eead33e772e8978f1e371b516d1d6a91e8fa1b5860249b6
font_01_sfnt_off00005a04.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5A04 9424 bytes
SHA-256: 7ea61ba35eb106f619d89851c3883cb906d1589319991080a86f513e98aaf6b5