Malicious PDF — malware analysis report

Static analysis result for SHA-256 90101a1d3f1e98f1…

MALICIOUS

PDF

75.6 KB Created: 2020-12-26 09:22:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-02
MD5: c89cf98923cf36aa12f6752af47e1ef9 SHA-1: ee8cddbf2ca4f8e3a5bc35d0efe8a06276b00733 SHA-256: 90101a1d3f1e98f1fe4f8046c3fda0dda2aec217c58a2687c8f1d28c6cb77278
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and ML classifiers, indicating a high likelihood of malicious intent. The heuristic 'PDF_SEO_LINK_FARM' suggests the document is designed to host a large number of external links, likely for SEO manipulation or to distribute further malicious content. One of the embedded URLs, 'https://trafffe.ru/aws?utm_term=debt+validation+letter+template+uk', directly relates to the document's apparent theme of debt validation, suggesting a phishing or scam attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/aws?utm_term=debt+validation+letter+template+uk PDF link annotation
    • https://cdn.sqhk.co/bodovukig/BHhghjb/lara_croft_relic_run_mod_apk_unlimited_money.pdfIn PDF document text
    • https://rewemekekebaz.weebly.com/uploads/1/3/1/4/131406535/4202832.pdfIn PDF document text
    • https://cdn.sqhk.co/gujadozede/ahjf1ih/wapekesoti.pdfIn PDF document text
    • https://cdn.sqhk.co/bibunifez/RRdwaSm/memimiratuxot.pdfIn PDF document text
    • https://cdn.sqhk.co/kebubupoxiz/ngjUnNZ/disorderly_synonym_adjective.pdfIn PDF document text
    • https://ligenoleka.weebly.com/uploads/1/3/4/4/134496601/nuwufoti-firidaxufuwo.pdfIn PDF document text
    • https://japiloxekafu.weebly.com/uploads/1/3/4/4/134480389/283487.pdfIn PDF document text
    • https://cdn.sqhk.co/kubezuvare/ahjchgj/war_of_worlds_2005_imdb.pdfIn PDF document text
    • https://cdn.sqhk.co/pavujakorige/0jj01xL/ncert_science_book_class_9th_solution.pdfIn PDF document text
    • https://tokunebejuz.weebly.com/uploads/1/3/4/3/134323577/dubezago.pdfIn PDF document text
    • https://cdn.sqhk.co/dorusafe/gi2b2ig/pivubijirironiz.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/kakekojezutok/compass_rule_adjustment_method.pdfIn PDF document text
    • https://s3.amazonaws.com/fajixe/jacksmith_cool_math_unblocked.pdfIn PDF document text
    • https://s3.amazonaws.com/zetubakuz/kbb_used_cars_pricing_report.pdfIn PDF document text
    • https://s3.amazonaws.com/mozirolinitaje/vopatenasud.pdfIn PDF document text
    • https://s3.amazonaws.com/farezelof/xolewebodabuvavekuv.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb33.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB33 5188 bytes
SHA-256: 54011d7fdd6339c9621d11bb7899d8db0b61572d1b007fba28b549b9d47ef458
font_01_sfnt_off0000fcc9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFCC9 10776 bytes
SHA-256: 56027ea43640446189ad027945bdfd5a23db04cb8b0e36d0d25a46da984fb8b8