Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6b7d22b8f0e0e34…

MALICIOUS

PDF

45.6 KB Created: 2020-11-08 02:10:30 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 86349185c2a9591255d22e71308a2314 SHA-1: b4d5e142c06510e474bee7481913c5ea5150ae77 SHA-256: c6b7d22b8f0e0e34ddbb45aacb8cbf57bf50cb3881554293221825a1da07f1e9
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded links, including a primary link to 'traffset.ru' which is flagged as suspicious. The PDF_SEO_LINK_FARM heuristic indicates a large number of external links, suggesting a link farm designed to direct users to potentially malicious content. The ML_NYX_PDF_MALICIOUS model also strongly flagged this file. While no scripts were explicitly extracted, the structure and embedded links point towards a phishing or content-luring attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/aws?keyword=recover+deleted+g+suite+account
    • https://cdn-cms.f-static.net/uploads/4446286/normal_5fa722f733269.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/d2cbd0a0-d281-407d-8238-5fd8cd5b435d/49709130365.pdf
    • https://zivujege.files.wordpress.com/2020/11/2878917950.pdf
    • https://solavaje.files.wordpress.com/2020/11/zedutasotisawafunob.pdf
    • https://baginalikut.files.wordpress.com/2020/11/nopim.pdf
    • https://uploads.strikinglycdn.com/files/0b26de72-3d5b-4f09-8ce3-119b2def57d6/85949026500.pdf
    • https://zowawalu.files.wordpress.com/2020/11/dapilako.pdf
    • https://botebofeji.files.wordpress.com/2020/11/15963812645.pdf
    • https://lodoxepal.files.wordpress.com/2020/11/vibinofa.pdf
    • https://demugomido.files.wordpress.com/2020/11/17890759962.pdf
    • https://s3.amazonaws.com/rekorewexidiwo/administrao_financeira_e_oramentria_3d_2018.pdf
    • https://mopapuwo.files.wordpress.com/2020/11/nivoxanovibidimoriti.pdf
    • https://muregeboseri.files.wordpress.com/2020/11/31148695910.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000746b.bin
6e2a8bf77ea8dce9d31d8b3b13d1d9db7b7b911fa8c2474aba762a05bd41ce4a
pdf-font-stream PDF embedded font (sfnt) at offset 0x746B 5176 bytes
font_01_sfnt_off00008623.bin
e68516ff6c4ce295ca4dade2140e9cbeb651b51cc516421dae70c3600840236a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8623 10460 bytes