Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca5995b98adf66c0…

MALICIOUS

PDF

47.4 KB Created: 2020-11-06 01:39:38 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b6383e3000e9a536bba724516a76f605 SHA-1: 76e00ebe72d9a1ccb98ebe4ceec6cff8447cc35e SHA-256: ca5995b98adf66c0b8de818aeae07c2ad060b86113e4c5ad46163139287e6321
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and contains a large number of external links, indicating a potential link farm or redirection to malicious content. The document body, though partially corrupted, contains URLs that are likely part of this scheme. No scripts were extracted, but the presence of numerous external links suggests an attempt to direct users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/123?keyword=gym+community+discourse
    • https://cdn-cms.f-static.net/uploads/4378853/normal_5f98656f62442.pdf
    • https://cdn-cms.f-static.net/uploads/4377931/normal_5f918af609313.pdf
    • https://cdn-cms.f-static.net/uploads/4374371/normal_5f8dda3c16594.pdf
    • https://votuwokikinoso.weebly.com/uploads/1/3/4/4/134466575/xovivov.pdf
    • https://cdn-cms.f-static.net/uploads/4384461/normal_5fa415b3c565a.pdf
    • https://cdn-cms.f-static.net/uploads/4365551/normal_5f86fa2d1154d.pdf
    • https://cdn-cms.f-static.net/uploads/4392857/normal_5f96689f89ee0.pdf
    • https://cdn-cms.f-static.net/uploads/4393625/normal_5f966a6d98154.pdf
    • https://cdn-cms.f-static.net/uploads/4383450/normal_5f93546417a74.pdf
    • https://cdn-cms.f-static.net/uploads/4366385/normal_5f886d489a56d.pdf
    • https://cdn-cms.f-static.net/uploads/4414501/normal_5fa33d4f0e42a.pdf
    • https://cdn-cms.f-static.net/uploads/4377095/normal_5f9ace866f0d4.pdf
    • https://cdn-cms.f-static.net/uploads/4408879/normal_5f9d27872c950.pdf
    • https://cdn-cms.f-static.net/uploads/4372702/normal_5f92590c2def8.pdf
    • https://wabebapag.weebly.com/uploads/1/3/4/3/134335427/jilutigapebeki-dugulisirubowus-goterup-zizovi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0485/0053/9554/files/tema_untuk_iphone_8_emoji_keyboard_apk.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007df8.bin
c66d0fd624a128f1dbf135be9a53aa712e2b8dd6c49e852391615d20d18a0371
pdf-font-stream PDF embedded font (sfnt) at offset 0x7DF8 4976 bytes
font_01_sfnt_off00008edd.bin
94c88d9ea52202b79f02dddfa4f3d2c2eaba8a13bb8c2f8b627de4a184ece7eb
pdf-font-stream PDF embedded font (sfnt) at offset 0x8EDD 10008 bytes