Malicious PDF — malware analysis report

Static analysis result for SHA-256 58d8af2ef579ee5d…

MALICIOUS

PDF

60.6 KB Created: 2020-11-11 13:44:17 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 008ac004cc57fe695cc230c803e008b1 SHA-1: 1e2ca5a22e5fe38ae182dab993a0a87ebf2401d2 SHA-256: 58d8af2ef579ee5d84214d15e8f558284a578a4eb26cf3ddc12461e5a66c5087
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains heuristics indicating it is a malicious phishing document and hosts a link farm. The embedded URL 'https://traffnew.ru/strik?keyword=pelis24+estrenos+de+cine' is likely the primary lure, directing users to a site disguised as a movie release portal. The PDF also references a large number of external PDF links, suggesting a coordinated effort to distribute malicious content or SEO spam.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/strik?keyword=pelis24+estrenos+de+cine
    • https://cdn-cms.f-static.net/uploads/4405185/normal_5faa56c1e7c5f.pdf
    • https://sebonegipuwi.weebly.com/uploads/1/3/4/1/134108682/jedonureketolam-sobikesitazezuf-loretebovabof-xokefuno.pdf
    • https://cdn-cms.f-static.net/uploads/4476941/normal_5fab86f708443.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/77ec32cb-9bd8-4f92-8bb2-6b83f8d7b1d1/stt_v_xe_exciter.pdf
    • https://uploads.strikinglycdn.com/files/be8e4aff-f652-4115-9c25-2753463bd3cd/miruwogekiwuxipexodelima.pdf
    • https://uploads.strikinglycdn.com/files/85279bb4-eabc-4dc7-b995-ba07becde800/vofasok.pdf
    • https://uploads.strikinglycdn.com/files/1a42424e-910a-4540-a709-55b1f623b8e2/rapport_de_stage_technicien_informatique.pdf
    • https://uploads.strikinglycdn.com/files/6419dbcb-4d0b-4708-ad04-8b1c6b730585/80212198894.pdf
    • https://uploads.strikinglycdn.com/files/4330785c-dacb-4589-8579-1253ad349910/prisma_pentagonal_formula.pdf
    • https://uploads.strikinglycdn.com/files/5f1c7344-6f67-4141-936d-3c9efcfac0b7/15969344487.pdf
    • https://uploads.strikinglycdn.com/files/629f35fc-690a-46c1-b463-96684df5f4e2/reys_survival_guide.pdf
    • https://uploads.strikinglycdn.com/files/ee758272-c080-4dfd-bac8-a5d2ff5961df/lukugexepimuz.pdf
    • https://uploads.strikinglycdn.com/files/3e021a5b-5a29-42e5-bf9f-f048ae382c4c/novidisagezidobiguvemisaz.pdf
    • https://uploads.strikinglycdn.com/files/3a7a10ba-e870-4784-bb2f-5b5e1ff01918/six_feet_of_the_country.pdf
    • https://uploads.strikinglycdn.com/files/693e8ea8-3ac1-4bfe-93d0-b59baef8cbf6/sotikosobusesot.pdf
    • https://uploads.strikinglycdn.com/files/b195a372-832c-4331-b1ca-75bf30999417/65564577895.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b4e3.bin
e513eeb3adec18a5df1ab19ad57670144a5dce5898cb1f9408f6934c63228474
pdf-font-stream PDF embedded font (sfnt) at offset 0xB4E3 4944 bytes
font_01_sfnt_off0000c5cc.bin
722d7d582931f6d03c644465b912e9ca8aac99fa416371afb152fd97bfe729df
pdf-font-stream PDF embedded font (sfnt) at offset 0xC5CC 9668 bytes