Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f0a70c2d4e18bed…

MALICIOUS

PDF

87.6 KB Created: 2020-11-11 13:43:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: 836ce19c4d3f594c1c082fceb7be3adf SHA-1: 6cf94d6ca95f82ce70072bb28595192e8d94925d SHA-256: 7f0a70c2d4e18bed99e9655505232d3530eb94047bff612c1f7143756f8aa84a
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a significant number pointing to a redirector URL (https://trafffi.ru/123?keyword=sleeping+venus+giorgione). This behavior is indicative of an SEO link farm or phishing lure. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/123?keyword=sleeping+venus+giorgione PDF link annotation
    • https://vamekatowozi.weebly.com/uploads/1/3/0/8/130814347/38af4a71d10.pdfIn PDF document text
    • https://pefuxagofir.weebly.com/uploads/1/3/4/3/134359429/b45ead2990d3.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/64dc099d-671f-4051-80be-77684d4bba00/luraza.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ea37e979-e847-42c1-8730-b98cd530cb11/pawonip.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7a981d75-97cf-45d7-a4f2-6dcc1b0cade6/9388566288.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cd96e8c8-9b00-46a5-b868-9655b642ed16/korisisufawelerid.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/726563a3-5adc-4c19-8e90-42a23a08e418/77415021703.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/af19b95e-154b-46df-859c-4e2d16164f61/bejerivereke.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/308f4888-85fd-4147-8ac2-8560859ead70/wobewosafowoxusa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a01c20bf-32eb-4921-80d3-a72c252ae2de/tipos_de_materiales_para_techos.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/90b226fb-7d1c-4553-8154-71b64e0bbc24/31890793345.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/025a9922-5de1-45b4-bbcb-b31372824d80/zane_addicted_free.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d582.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD582 4680 bytes
SHA-256: 35b63c0b7dfbb139c5f6e7b6d86f34e6c431dd9cd32c6d53feebba2e7b5f6619
font_01_sfnt_off0000e5d4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE5D4 4940 bytes
SHA-256: b45a17d81e89eb3a1bd64f64735ee32fe82ebcd4c3c7ada95e149525c01f3d57
font_02_sfnt_off0000f6bf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF6BF 15004 bytes
SHA-256: e2b72d60b4d46c15d01342a38ee3f306502cb1dbfbcc6bc71d6f7d12684bc46a
font_03_sfnt_off000128c2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x128C2 16344 bytes
SHA-256: bea6f42cec663bc0201f713ee0f13a91c6b80273bfcc59e4b9c7163f39462f17
font_04_sfnt_off00013e8d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13E8D 6504 bytes
SHA-256: 04230e5eca4c5e2aafcb9ec34e44029dc6baacd765322392982da7738ae8f03e