Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b28c49eac768ac6…

MALICIOUS

PDF

144.6 KB Created: 2020-11-19 02:16:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-26
MD5: a9b3a92a4b39114e639423a49a3b0374 SHA-1: eb0f874b2a27384fd3e0836c3c7da538c0e3ceab SHA-256: 9b28c49eac768ac62725ad1ea32affed5be6d2af8665bd65e78bdd3f045e4e4e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a critical heuristic identifying it as a link farm. The primary URL, 'https://trafffe.ru/strik?utm_term=quest%25C3%25B5es+sobre+o+renascimento+cultural', suggests a phishing or spamming attempt disguised as content about cultural renaissance. While no scripts were explicitly extracted, the PDF structure and extensive external linking are indicative of malicious intent, likely to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/strik?utm_term=quest%25C3%25B5es+sobre+o+renascimento+cultural PDF link annotation
    • https://pidadilux.weebly.com/uploads/1/3/4/6/134666204/bazarerin-surilugajexu-jusibut-jopaxig.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4388420/normal_5f90813c05586.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4464870/normal_5fa94cfa1ecd3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391649/normal_5fa9afb60326b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368985/normal_5f9cffd106a2a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4454984/normal_5faf6dc3ac97c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/mejados/51821863795.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fbdf5e1e-279a-47ed-a5f0-9fcbf881e8e6/gilivedupiduponagowaxal.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4709b148-545a-4fb8-88b7-e51966fed2c0/75584486903.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/47eea0e3-d9c3-496c-95db-3c24484fd446/monepemovisimewimiloti.pdfIn PDF document text
    • https://s3.amazonaws.com/farezelof/lazobotuxuxeresa.pdfIn PDF document text
    • https://s3.amazonaws.com/vexosafugunu/warebafexebiwoda.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/98e6d9c9-8a36-401b-b8b2-b29c9d7a6c1e/tixowisixolobejarevuvan.pdfIn PDF document text
    • https://s3.amazonaws.com/lovomijelun/69753087308.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/319d0cf1-ccfe-47f8-8228-901e06b2ec5d/67839973503.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001f778.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1F778 5364 bytes
SHA-256: 6cc0282f8ce9a67e43cf07fd996484bf9bad3e36fcc74628a86d5e030bdbc611
font_01_sfnt_off00020952.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x20952 13724 bytes
SHA-256: e737c09727e79114e4f6320754e762bf430f622eb3e828cc4f3ca1555ea89b2e