Malicious PDF — malware analysis report

Static analysis result for SHA-256 87dc1b467196f047…

MALICIOUS

PDF

72.8 KB Created: 2020-12-23 05:02:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f6b1217a1562a0672c76e27a66a21223 SHA-1: 540891daf4cedb229199bbaff19940b13ad6fecf SHA-256: 87dc1b467196f047898e1068d0f225eec1439a75f0e8b0cb70a0795d8e4b76e9
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by a ML classifier and ClamAV, indicating a high likelihood of malicious intent. The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM', with a primary suspicious URL pointing to 'traffking.ru'. This suggests the document is part of a phishing or SEO spam campaign, likely intended to redirect users to malicious sites or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/strik?utm_term=pentagon+jr+mask+buy
    • https://dugajivesunilo.weebly.com/uploads/1/3/4/8/134866737/1b4cc5c75cd.pdf
    • https://cdn-cms.f-static.net/uploads/4495240/normal_5faafc081536c.pdf
    • https://winomumamo.weebly.com/uploads/1/3/1/0/131070375/2522629.pdf
    • https://static.s123-cdn-static.com/uploads/4460954/normal_5fc75a21017ac.pdf
    • https://cdn-cms.f-static.net/uploads/4468819/normal_5faa0f2901aab.pdf
    • https://static.s123-cdn-static.com/uploads/4488103/normal_5fc9680223186.pdf
    • https://cdn-cms.f-static.net/uploads/4368469/normal_5fbb30d3a5f96.pdf
    • https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/vabovezu-dodamiw-gutagapaz.pdf
    • https://satizivuzaked.weebly.com/uploads/1/3/4/3/134383512/mefubiforuvumi.pdf
    • https://wipasajumavadus.weebly.com/uploads/1/3/4/7/134775966/7613680.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static1.squarespace.com/static/5fc14892f9866f3fd2d6f995/t/5fc5cedb3c6ccf69f32886a3/1606799069806/mortal_engines_book.pdf
    • https://static1.squarespace.com/static/5fc589c6405d5340f34924f2/t/5fcc18260ab5d62febe0c048/1607211047500/spotlight_room_escape_level_2_paper.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf55524e98326c02077cee/1606374739050/joe_mellen_borehole.pdf
    • https://static1.squarespace.com/static/5fe27c48032a635f4054ac28/t/5fe2a169ff1c114acfc702a7/1608687977285/maths_and_physics_tutor_textbook_answers.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000df6f.bin
1db39c62ee557ce967dc32791332d5ce9c9961325378dc7432f08bc4c1dc7709
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF6F 5356 bytes
font_01_sfnt_off0000f1a6.bin
fed7311c72f18ca52e5eef869068a0d5be081d0e8636b8e41e63295a5b0194c7
pdf-font-stream PDF embedded font (sfnt) at offset 0xF1A6 10896 bytes