Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8798c3df8e9bbe0…

MALICIOUS

PDF

71.0 KB Created: 2020-12-26 19:40:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: 8f056f1dff97eeb0b274be6992bfb71a SHA-1: b00eae3fe8b8aeff063a12bc3265e99d0b8cd16a SHA-256: a8798c3df8e9bbe0b6a54855b57e5a4cf944e0f1b3853d559119a2a805700f03
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a prominent heuristic identifying it as a 'PDF_SEO_LINK_FARM' and 'PDF_SEO_UTM_REDIRECTOR_LINK'. The primary malicious URL identified is 'https://traffnew.ru/123?utm_term=difference+between+vegetable+chow+mein+and+lo+mein', which is likely used for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/123?utm_term=difference+between+vegetable+chow+mein+and+lo+mein PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4471704/normal_5fd73a0d7133e.pdfIn PDF document text
    • https://wajigigo.weebly.com/uploads/1/3/4/5/134588105/9213219.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379733/normal_5fc22a30419a4.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4483335/normal_5fcfb042d9ed4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4376601/normal_5fbb69068c9cd.pdfIn PDF document text
    • https://peniwomafases.weebly.com/uploads/1/3/4/7/134705361/2507955.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4407562/normal_5fe3b32b4e741.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366360/normal_5f907c8ba73e4.pdfIn PDF document text
    • https://lovaxases.weebly.com/uploads/1/3/4/6/134685664/4112036.pdfIn PDF document text
    • https://dokakida.weebly.com/uploads/1/3/1/3/131380589/tonewe.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/19246e2e-56b8-48ef-bb11-970433826238/pukiju.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4394e45e-049d-4fb2-b66f-2541e20f5903/tiktok_mashup_clean.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c0b39d58-fbdc-453a-857d-8df27ec3a5bd/95028046609.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cd5b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCD5B 3172 bytes
SHA-256: 0396bd5c23ae220e096cd2eb9800fce9872a5ab58eb7ef612c50267f83eb031a
font_01_sfnt_off0000d8ab.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD8AB 5548 bytes
SHA-256: b8e71b9b7cd153b018bc1da298f8ceca815f253b8cccd3fd0298531979de2563
font_02_sfnt_off0000eb7b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB7B 10236 bytes
SHA-256: c547a6757939749b0abbf04eafaa97003dacf943f65bad0f6064d5764eb08a17