Malicious PDF — malware analysis report

Static analysis result for SHA-256 8aea0494d7e5433d…

MALICIOUS

PDF

67.6 KB Created: 2020-11-17 09:42:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 17671719feaac46a8912eecbff0e8f01 SHA-1: d3a1c82a55fd3c70c514d624b81008c731a30d62 SHA-256: 8aea0494d7e5433d4f91367810c2956df6101b3c92044ba20f17023806584224
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by multiple heuristics, including a critical finding for a malicious redirector link and a PDF link farm. The ML classifier also returned a high confidence score. The embedded links, particularly the one pointing to 'gettraff.ru', suggest an attempt to lure the user to malicious infrastructure. While no scripts were explicitly extracted, the PDF structure and link farm indicate a likely phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/strik?utm_term=griffon+mount+guide
    • https://vesexifog.weebly.com/uploads/1/3/4/4/134491049/d7ea8bb4d1d.pdf
    • https://texitanoz.weebly.com/uploads/1/3/0/7/130739996/35d1cd.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/tuxenipup/24664223985.pdf
    • https://s3.amazonaws.com/numunenoji/printable_worksheets_for_possessive_adjectives.pdf
    • https://uploads.strikinglycdn.com/files/2c43f0c2-497a-44a9-b6b7-ceb76ddd3421/27411052587.pdf
    • https://s3.amazonaws.com/sowewazulejewi/sunrise_middle_school_website.pdf
    • https://s3.amazonaws.com/felasorarabipis/rogeramolaregelanunus.pdf
    • https://s3.amazonaws.com/bugutaj/tujozo.pdf
    • https://uploads.strikinglycdn.com/files/0abcc58b-5481-4ef2-821a-22a85a20aaee/cornelia_street_piano_sheet_music.pdf
    • https://s3.amazonaws.com/pevarijidasalop/derufilavumazemirizuwabat.pdf
    • https://s3.amazonaws.com/pewibim/16706072968.pdf
    • https://uploads.strikinglycdn.com/files/98b32570-da88-4b93-bd1f-5c6e608eb79d/kawazavidoribapat.pdf
    • https://uploads.strikinglycdn.com/files/0609cb36-2afb-4ff2-8662-c028bae8c02b/vorirekanometo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ce62.bin
5691d0e3c6c391bdb778eb85f4a94bded3d207dccb134824d00e061bd191ed05
pdf-font-stream PDF embedded font (sfnt) at offset 0xCE62 4836 bytes
font_01_sfnt_off0000dec5.bin
aaa9e41ee0e2bf52be9eb9ea06117a28d71e03a88623c55c53f8616c3c776ac1
pdf-font-stream PDF embedded font (sfnt) at offset 0xDEC5 10396 bytes