Malicious PDF — malware analysis report

Static analysis result for SHA-256 82c7add65cd3a0c3…

MALICIOUS

PDF

70.4 KB Created: 2020-12-09 20:39:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-26
MD5: 3c311644003ad6167d8aaa824b39cc5f SHA-1: 1c2090e46a84f605e641dc3cc9fa9c023550b84d SHA-256: 82c7add65cd3a0c34fa6e8d770a5c5305a4ae3131318079a6b8f21dd1335e4e1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was identified as malicious by ClamAV and an ML classifier, with heuristics indicating it contains a large number of external links, potentially for SEO farming or malicious distribution. The embedded URL 'https://trafffi.ru/strik?utm_term=monster+legends+cheats' suggests a phishing or scam attempt related to game cheats. While no scripts were explicitly extracted, the PDF structure and the presence of external links are indicative of a malicious document designed to lead users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=monster+legends+cheats PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4403413/normal_5f98ce6fcca3b.pdfIn PDF document text
    • https://mitixofixomu.weebly.com/uploads/1/3/4/3/134333727/5122364.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf4c874f98375720d6994c/1606372492484/dezodokasiwusa.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc042db8787e8798968ae67/t/5fc0e8bf18e72e5fdbf89553/1606478015875/vomagajositejelerozenosuj.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc6adfcbdb33045eeea6878/t/5fceb88ceb7447177aad0326/1607383181826/encyclopedia_dramatica_site.pdfIn PDF document text
    • https://s3.amazonaws.com/donake/bedodogimokozala.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc27aecc14dfd36fefb8ed8/t/5fca31bcbe6684539df40525/1607086525427/90886888773.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc2ae6a9955c744b5470351/t/5fc4e607bc819f1cf4725659/1606739463881/parable_of_sheep_and_goats_video.pdfIn PDF document text
    • https://s3.amazonaws.com/baxegezivumi/variance_versus_sd.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc5cfc716f6d44b07e04109/t/5fcde43deb18547f4ba6bbda/1607328829853/mens_hairstyles_long_thick_wavy_hair.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc1511bbda9c57a97c10f7b/t/5fcd5329fe657040d5a1ba78/1607291689587/company_of_heroes_2_gameplay_2020.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc2de6511f6a41984928cab/t/5fcbf3ad2bc78848529de96e/1607201710608/rameku.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0f08c104edf1d7780fb42/t/5fcd391a1e1a4d7de136629a/1607285019067/dragon_ball_z_battle_of_gods_before_super.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cdc3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCDC3 4944 bytes
SHA-256: 4b4a324db63abec96f3ae17a196525511241a4172e147323e917a79132351789
font_01_sfnt_off0000de8a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDE8A 9540 bytes
SHA-256: 137659f1bf0fe898c1d722a03c477f83512c1f9ed5495be2e04ee574a3828d0a
font_02_sfnt_off0000ff1d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF1D 4324 bytes
SHA-256: 9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2