Malicious PDF — malware analysis report

Static analysis result for SHA-256 b08c019494a7e2f0…

MALICIOUS

PDF

99.0 KB Created: 2020-11-08 12:49:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bc21b292609b3f34ae5e1145f6eab582 SHA-1: 71fe144b141ea4f64c3a94865b8833e7cbf11185 SHA-256: b08c019494a7e2f00dede86e0aa9a17592b702436ff80449222b055d29b0268e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are to other PDFs, suggesting an SEO link farm or spamming operation. One of the embedded URIs, 'https://trafffi.ru/123?keyword=sort+the+court+game+free+to+play+no+download', is directly associated with the document's content. The ML classifier strongly flagged this PDF as malicious, and the presence of embedded URIs indicates potential for malicious redirection or content delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/123?keyword=sort+the+court+game+free+to+play+no+download
    • https://cdn-cms.f-static.net/uploads/4374968/normal_5f9afaaf1a934.pdf
    • https://cdn-cms.f-static.net/uploads/4367310/normal_5f8a9c8d5f415.pdf
    • https://cdn-cms.f-static.net/uploads/4380383/normal_5f8cbe1c71048.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/9764f2ec-ff84-4a22-ad91-4a91ce6efc4f/6065190595.pdf
    • https://lodoxepal.files.wordpress.com/2020/11/vibinofa.pdf
    • https://wijufedu.files.wordpress.com/2020/11/masopigefuzidef.pdf
    • https://gozevawu.files.wordpress.com/2020/11/tuziguxixemuzuvu.pdf
    • https://fumawelim.files.wordpress.com/2020/11/74601884378.pdf
    • https://direfaxa.files.wordpress.com/2020/11/44616410186.pdf
    • https://mutozofe.files.wordpress.com/2020/11/67728004733.pdf
    • https://wiludilake.files.wordpress.com/2020/11/xomew.pdf
    • https://dojofenuf.files.wordpress.com/2020/11/xixeludeposixalitikada.pdf
    • https://gunajuluk.files.wordpress.com/2020/11/18862362581.pdf
    • https://zojemadej.files.wordpress.com/2020/11/73587489466.pdf
    • https://gesitupar.files.wordpress.com/2020/11/unnamed-file.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000120ab.bin
52eab3a18e50b6a0f39a79dc01e85bbae5024ff09eeacc467fb019f3b4d40889
pdf-font-stream PDF embedded font (sfnt) at offset 0x120AB 11544 bytes
font_01_sfnt_off00014718.bin
86ab74624669069abeec5a4827d0a2a3114d80c7f4d63160466fae5d4ce7ff85
pdf-font-stream PDF embedded font (sfnt) at offset 0x14718 5688 bytes
font_02_sfnt_off00015a64.bin
51d934c1381ce7a2206bf03ba89845d9f5e443a0e019fb364e532f0686c85d6e
pdf-font-stream PDF embedded font (sfnt) at offset 0x15A64 10580 bytes