Malicious PDF — malware analysis report

Static analysis result for SHA-256 b13bbe1921ff837a…

MALICIOUS

PDF

70.6 KB Created: 2020-12-23 00:59:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: 3271cd50be5893852a85847e5a2ad56e SHA-1: 1ca11371576e35ef9dba6bf802315a0e0a061321 SHA-256: b13bbe1921ff837abe4e789d3bb5ec7f577607d5426fe66ec4710037f15e0d90
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with one prominent URL pointing to 'trafffi.ru'. This, combined with the ClamAV detection and ML classifier flagging it as malicious, strongly suggests a phishing or spamming campaign. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, likely for SEO manipulation or to distribute malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=name+generator+based+on+personality+traits PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4370540/normal_5f9a9869662f2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4419836/normal_5fbbdd51441f1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420903/normal_5f97530c8e0ae.pdfIn PDF document text
    • https://zukigepuzena.weebly.com/uploads/1/3/4/5/134593101/lelej.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4413705/normal_5fdd099f26d23.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/fc212071-b6af-465f-83b6-a8ebd98f8592/53423902616.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8f444821-ee99-4673-9a05-4a0c16e531a4/viva_video_apk_file_free_download.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fceaf99da8bba4008cd01c6/t/5fd082222f29925fbb50af2e/1607500323684/served_up_with_love.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bce726e4-a3b7-4e7c-8187-17a9d8f90f62/dijeditajabogaz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9a8bdb49-834a-40b5-b7b1-08f96650a52e/pewojopebideta.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc1343bd26ff1194f75a191/t/5fcc5edf920f47545b8a3fd0/1607229154513/10150330607.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc29d2a403f5353fda0c22b/t/5fc8feb8f08cdc14c5cb46d7/1607007930019/coloring_books_flowers_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9e791c04-c124-4471-bff0-524ec7e994c4/lukas_graham_7_years_old_song_lyrics.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ca78.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCA78 5280 bytes
SHA-256: 6490fc611f47d5cc2188410876a1c981c12e1a2bb3234bd9513c574cdd0372fe
font_01_sfnt_off0000dc4b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC4B 10316 bytes
SHA-256: 55adf3deaceb0488abeef0d171ac4e5f6824b5fbc3ad3fe001ec0d7f07d74821
font_02_sfnt_off0000ff55.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF55 4324 bytes
SHA-256: 0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333