Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0fe9b2c7fa69edd…

MALICIOUS

PDF

67.7 KB Created: 2020-11-27 09:33:59 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9f39a56ff31f18b780a2a5177c64bfd7 SHA-1: d3aaa51c7e5ade49861af7bfff0624c1baa9ad3b SHA-256: d0fe9b2c7fa69edd18d25653930b61caed64704481519eb43b7af94f10c3edf0
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous links to external websites, with at least one identified as a malicious redirector. The document body, though heavily obfuscated, suggests a lure related to 'minecraft earth guide reddit'. The presence of multiple PDF links and a critical heuristic firing for a malicious redirector indicates a phishing or scam attempt designed to lead users to malicious infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/aws?utm_term=minecraft+earth+guide+reddit
    • https://doxazijizule.weebly.com/uploads/1/3/4/6/134640144/petosu.pdf
    • https://paviliwele.weebly.com/uploads/1/3/4/4/134489687/pitoguzuzanez.pdf
    • https://bavejojonosepes.weebly.com/uploads/1/3/1/3/131380601/gemugi_tevugalojaboxi_pasuwog_zolewomunuru.pdf
    • https://mizitixas.weebly.com/uploads/1/3/4/5/134589849/buzopukijakurugef.pdf
    • https://cdn-cms.f-static.net/uploads/4370077/normal_5fb40948dde3b.pdf
    • https://cdn-cms.f-static.net/uploads/4380528/normal_5f90ae8ce77c6.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/tigovatolis/xupobajadefetodizivedu.pdf
    • https://uploads.strikinglycdn.com/files/093f638c-f3c2-41b2-93e5-2e4754d3b56b/how_long_to_beat_amnesia.pdf
    • https://s3.amazonaws.com/metakibeme/barson_yaaron_song_free.pdf
    • https://s3.amazonaws.com/sasufufa/punemiwiridusavulob.pdf
    • https://s3.amazonaws.com/vuliwisuwig/chemical_engineering_magazine.pdf
    • https://uploads.strikinglycdn.com/files/46056310-28a2-4dc7-9d82-5a0699ca5369/27313909223.pdf
    • https://s3.amazonaws.com/kevava/bsa_medical_form_part_d.pdf
    • https://uploads.strikinglycdn.com/files/e442965d-cdeb-4188-ba3a-832ba8cca665/visitador_medico_computrabajo_urugua.pdf
    • https://uploads.strikinglycdn.com/files/b4876ce3-9cfd-43b2-b2f6-eec631bbb6c0/tujubisazokafuwotigol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000caa7.bin
ea19c9d5c35547e29dc9e920f5e142db31258cc8c699065d758ac5fa1deff826
pdf-font-stream PDF embedded font (sfnt) at offset 0xCAA7 5076 bytes
font_01_sfnt_off0000dbf6.bin
d0aaa0b4ca42876a2bb4ff73da75b07f6b80419b4f647edc7d619f0acff06d80
pdf-font-stream PDF embedded font (sfnt) at offset 0xDBF6 11292 bytes