Malicious PDF — malware analysis report

Static analysis result for SHA-256 a85706b7a538cbd3…

MALICIOUS

PDF

58.4 KB Created: 2020-12-17 07:54:39 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-15
MD5: eeb1c7498ac53d1a64bd9e964c226dcd SHA-1: bca4367376f740e3226a47bece95f5bce8265d29 SHA-256: a85706b7a538cbd3a60739498018e2e81299d0f2ec2dbb321a5727d4e7e98337
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with one pointing to a suspicious domain ('trafftec.ru'). Heuristics indicate a link farm and ClamAV detection as 'Pdf.Phishing.Trojan'. The ML classifier also strongly flagged this PDF as malicious. While no scripts were explicitly extracted, the presence of embedded URLs and the overall structure suggest an attempt to redirect the user to a malicious site, likely for phishing or to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/strik?utm_term=trb+annual+meeting+2020+program PDF link annotation
    • https://tibiwurab.weebly.com/uploads/1/3/2/6/132695994/2762176.pdfIn PDF document text
    • https://xisuviwilizej.weebly.com/uploads/1/3/4/3/134320176/letikajevurikakawi.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://static1.squarespace.com/static/5fc009dd8787e87989674e7e/t/5fc58dfff8cdb769c6a1c985/1606782465736/88286746261.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6f58568d-fc61-4818-9157-b42b18cb7d23/kotasozedevamilopamobuku.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fb2da99e-2cc8-427d-b034-f9fa2ed007da/xifuxixemamebesitisixive.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3cab9551-c0b5-4ed9-ae6d-1c537a26c184/types_of_centrifugation_techniques.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/078133fb-f7d5-4389-a3fd-ecca4b04deac/animal_jam_journey_book_cheats_bahari_bay.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2bca39a8-8bc7-44f0-a3b6-2792be4dc9c5/8384308014.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5cd16372-078a-414a-beda-13613f599cdd/togojonozefot.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2c74c04f-7f23-429f-b9cb-5ecaeb7abf64/lenonunoge.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7a78596b-4e8a-4846-9981-6acdaa725bac/32266558698.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/41de7c65-1f26-4ee4-88be-7a9377687088/13846566146.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe1074f8cdb769c6aacb76/1606291574001/hyatt_regency_cambridge_overlooking_boston_cambridge.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000aa89.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAA89 5324 bytes
SHA-256: f57084cb183b836b932508637e938e23b31d9c047348d28438b9d518f216d8f2
font_01_sfnt_off0000bc8b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBC8B 9544 bytes
SHA-256: 11b11ddd82c34f2744c97f7693a4436811ab1f25e5f54085786a24e50bae105d