Malicious PDF — malware analysis report

Static analysis result for SHA-256 9480941caae4a3a1…

MALICIOUS

PDF

72.3 KB Created: 2020-12-14 22:14:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7b1fc84c62e7ef7a114cf2f3bfe74745 SHA-1: d1e37076989e5a256d7c5be991d50dbae9dd2c99 SHA-256: 9480941caae4a3a1ffaecbb28b2225d0d29663b87fc561cc9c563cccb459841e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by ML classifiers and ClamAV, flagging it as a phishing trojan. It contains a large number of external links, many pointing to benign-looking PDFs, but at least one, 'https://traffnew.ru/123?utm_term=beach+wedding+hair+pieces', is associated with malicious activity. The document body is heavily obfuscated, but the presence of numerous external links suggests an attempt to manipulate search engine rankings or redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/123?utm_term=beach+wedding+hair+pieces
    • https://tivurenufetoza.weebly.com/uploads/1/3/4/2/134235987/7989346.pdf
    • https://zemutixo.weebly.com/uploads/1/3/4/8/134865820/674bd90.pdf
    • https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/pofexotokonadu.pdf
    • https://vivorewipaxuje.weebly.com/uploads/1/3/4/3/134365477/gijena-tabuvo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/geraromu/recyclerview_item_animation_android_github.pdf
    • https://s3.amazonaws.com/tirimofufemukat/toxalu.pdf
    • https://s3.amazonaws.com/rujabepifar/45326313887.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbd14fab24ece27e9136f2f/1606227194208/google_docs_frozen_2_english.pdf
    • https://s3.amazonaws.com/sizadagazagaj/82364251940.pdf
    • https://s3.amazonaws.com/susonanezaj/takubajolawagivifalekixab.pdf
    • https://static1.squarespace.com/static/5fc7a14d03f04e270fe5ad15/t/5fccf1145d2e6f3bda3e1bcd/1607266581815/vuxusawi.pdf
    • https://s3.amazonaws.com/jamokaroxoj/arduino_wifi_library.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d0a8.bin
470957bb6cb1e672fe61b9df9067ad7d0a53ae0d9adb1d409e536dc6cf49a344
pdf-font-stream PDF embedded font (sfnt) at offset 0xD0A8 5040 bytes
font_01_sfnt_off0000e1c1.bin
7831ce934fecb7a89c7172871df696a766fa6a4e6c7d4248c5b970734e8cc380
pdf-font-stream PDF embedded font (sfnt) at offset 0xE1C1 10840 bytes
font_02_sfnt_off0001065a.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1065A 4324 bytes