Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b71757d3dba7148…

MALICIOUS

PDF

73.7 KB Created: 2020-12-31 19:01:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: 8bdb5fc7b7a247b465941291df84b38e SHA-1: 27d9b1e190fd0d6664f62bc5638496d02e0e6ca4 SHA-256: 5b71757d3dba7148dbf8dba3f5e006083df9d54cbcb41302e0a4358a9724c7ff
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs, with a critical heuristic firing for a link to known malicious redirector infrastructure. The ML classifier and ClamAV also flagged the file as malicious. The presence of numerous external PDF links suggests a link farm or redirection scheme designed to lead users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffmen.ru/123?utm_term=1st+grade+science+teks In PDF document text
    • https://cdn-cms.f-static.net/uploads/4384026/normal_5fa2f60900eee.pdfIn PDF document text
    • https://wafumaxa.weebly.com/uploads/1/3/5/4/135400811/35c5cf41.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391000/normal_5f9a029fe0d19.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4378607/normal_5fb640923e51b.pdfIn PDF document text
    • https://zinikedefi.weebly.com/uploads/1/3/0/7/130740178/bf46d6.pdfIn PDF document text
    • https://samomalekadoj.weebly.com/uploads/1/3/1/4/131438786/d2e6357ae7bca0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367268/normal_5fb7c83e038ed.pdfIn PDF document text
    • https://nojabepeteguki.weebly.com/uploads/1/3/4/6/134669956/ririxabilose-xedopop.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/c57af8f7-db8f-4aca-8357-9871c548d6a2/dawaxikalidogu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8282d8e1-7625-4d9b-868a-ca3336eeb415/48210473992.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/32213897-3785-4b6e-8119-a5222d848732/lopaxufikunasemedo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/282cc059-0896-4741-8853-85c504aff88e/thirteen_reasons_why_discussion_questions.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b7584eb8-fff3-40af-bda4-d3ae7b9506f0/vigogexe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e417289b-8ae4-4e3d-8440-ff4d506987aa/97607521493.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9af29023-0cd6-496e-8331-4d4f9a440939/pathfinder_parade_armor.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d552.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD552 4776 bytes
SHA-256: 0dfd6f6f00b281880396399880f33c8e2f51483481d890af37aac8d6c9002e12
font_01_sfnt_off0000e58c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE58C 11256 bytes
SHA-256: bb2418b69bc1d19cd73c9734674a80bfa1301a584b94d009490f35f2e19a6814
font_02_sfnt_off00010bfb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10BFB 4324 bytes
SHA-256: 1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e