Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ed603e02f330730…

MALICIOUS

PDF

72.4 KB Created: 2020-11-22 23:41:38 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 96b8d63f1e7b7d62b80310dcc6c4c198 SHA-1: 1edb8f56955681a54b8ea4bb6c8867fb314c8b5a SHA-256: 5ed603e02f330730d571e501f761bc5cbe365a3d5d36809c85d940fa516e53fd
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, with at least one identified as a malicious redirector. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware delivery. The presence of numerous links suggests an attempt to create a link farm or distribute malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/123?utm_term=water+usage+calculator+worksheet
    • https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/f9007.pdf
    • https://cdn-cms.f-static.net/uploads/4392651/normal_5f959994ab44d.pdf
    • https://cdn-cms.f-static.net/uploads/4489404/normal_5fa8d933d5bbd.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/930964a1-624f-4714-bead-18708d8c98b2/sbarro_nutrition_facts.pdf
    • https://uploads.strikinglycdn.com/files/014c3456-c5ed-4a37-af64-7d10444c43b2/76689443232.pdf
    • https://uploads.strikinglycdn.com/files/9604852d-b88f-43cc-93a2-cb881ee5c649/little_hornets_preschool.pdf
    • https://uploads.strikinglycdn.com/files/6f8aa9ee-329a-4e5c-a1b7-25e23d1087d1/68057945057.pdf
    • https://s3.amazonaws.com/wujodibu/gagewesipuluvizus.pdf
    • https://uploads.strikinglycdn.com/files/f87fedb9-6b68-4c90-b224-ed96d07f5d83/equaes_exponenciais_exercicios_resolvidos_doc.pdf
    • https://s3.amazonaws.com/saxefi/thomas_advanced_vocabulary_and_idioms.pdf
    • https://uploads.strikinglycdn.com/files/45f509c3-21b9-4600-82d0-2f1041f7462f/cpc_practical_application_workbook_answers_2016.pdf
    • https://uploads.strikinglycdn.com/files/6a20fca7-054e-4337-846e-3914de2845b3/25935643369.pdf
    • https://s3.amazonaws.com/rurovikejigibu/suntuf_corrugated_polycarbonate_sheet.pdf
    • https://uploads.strikinglycdn.com/files/350a3dcd-51fe-4e40-bd3c-86169275c012/giwafuxedavonazibazefizi.pdf
    • https://s3.amazonaws.com/mubemutolewe/launcher_iphone_11_download_apk.pdf
    • https://uploads.strikinglycdn.com/files/970ecc22-d81c-4b42-8a11-83cd41d9361e/riwivodaba.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d049.bin
1c8563698e6ce16920ef846341433ee9955aabfbc9a88ae4450e465cde8d70f2
pdf-font-stream PDF embedded font (sfnt) at offset 0xD049 4960 bytes
font_01_sfnt_off0000e15b.bin
e41c528f670b023d22e07a511c4e90e8b01fca3f1476d47666e21e37300ab973
pdf-font-stream PDF embedded font (sfnt) at offset 0xE15B 11128 bytes
font_02_sfnt_off000106bb.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x106BB 4324 bytes