Malicious PDF — malware analysis report

Static analysis result for SHA-256 586b8f09b1d12b7a…

MALICIOUS

PDF

69.6 KB Created: 2020-12-19 03:46:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3846eeeb79abb6a625b3a5d424e1401f SHA-1: 198a97b829bbff689f5ac97c036f2622b0536fe9 SHA-256: 586b8f09b1d12b7a0abe8b3e1b06c7f5834ff57c252796db0b1acfd88da7bb7b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, with a critical heuristic identifying it as a PDF SEO link farm. One of the primary external URIs points to 'traffset.ru', which is likely a malicious domain used for traffic redirection or hosting further malicious content. While no scripts were explicitly extracted, the PDF structure and the presence of numerous links suggest an attempt to direct users to potentially harmful websites, aligning with spearphishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/strik?utm_term=middleton+fish+camp+cabin+rentals
    • https://vuterezupip.weebly.com/uploads/1/3/1/3/131380942/bakelufovobi.pdf
    • https://kekufekogaj.weebly.com/uploads/1/3/4/7/134768560/7505566.pdf
    • https://lajutiruwogow.weebly.com/uploads/1/3/4/5/134585316/zafuguji-gigil-zusus-wejudexelube.pdf
    • https://lumodafudewose.weebly.com/uploads/1/3/4/4/134480169/kanefu_jerofe.pdf
    • https://waziketezu.weebly.com/uploads/1/3/4/6/134648841/galowajotetis.pdf
    • https://jekazaveme.weebly.com/uploads/1/3/4/4/134470158/benejet-tinadenovomib.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/dazifozixawus/chromebook_11_g5_ee_service_manual.pdf
    • https://static1.squarespace.com/static/5fc5a3c8ab79f442f249d338/t/5fca18ed414f5e35238133a7/1607080178646/pokemon_heart_gold_randomizer_nuzlocke_download.pdf
    • https://uploads.strikinglycdn.com/files/b7640915-1843-475c-8d34-99db3f0422e4/hawthorn_park_ny.pdf
    • https://uploads.strikinglycdn.com/files/11c79c45-60d9-48ed-951e-0e7666a1e604/google_earth_moon_view.pdf
    • https://uploads.strikinglycdn.com/files/9e240670-b313-4038-9708-71c0f47aefd3/porigapigemewamo.pdf
    • https://uploads.strikinglycdn.com/files/afc89cdc-bd0c-4ca0-a531-6ad5e3b49269/81267662628.pdf
    • https://uploads.strikinglycdn.com/files/68b3c372-396a-42c3-8443-d2c2cd323d69/28188296196.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d339.bin
cf995abfd84b8bad8e8920837fbdd756ae3be36cadf70d6c716966a23db0edca
pdf-font-stream PDF embedded font (sfnt) at offset 0xD339 5540 bytes
font_01_sfnt_off0000e5ec.bin
e38b068dd8294e18cbceab9241664f700ec4de0f9259abdec0bffba21ed77689
pdf-font-stream PDF embedded font (sfnt) at offset 0xE5EC 10572 bytes