Malicious PDF — malware analysis report

Static analysis result for SHA-256 dae7de2486928202…

MALICIOUS

PDF

63.5 KB Created: 2020-11-21 17:36:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4eb1bdee97a1b74cd15ffdd9d1dd4239 SHA-1: 18cc5f49deef8dcc2f214c688e442fe3f5ff603c SHA-256: dae7de24869282025ae2573ff2e281369f5f8f1d68bc1c24ef65062874f060c2
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with at least one identified as a malicious redirector. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or to download further payloads. The document body is heavily obfuscated, but the presence of multiple external links points to a link farm or redirection strategy.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/123?utm_term=critical+moments+reflection+methodology
    • https://cdn-cms.f-static.net/uploads/4366623/normal_5f975671796b8.pdf
    • https://cdn-cms.f-static.net/uploads/4411218/normal_5fa22c38c13de.pdf
    • https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8554420.pdf
    • https://fizakilugoleji.weebly.com/uploads/1/3/1/4/131438405/4506559.pdf
    • https://netulomite.weebly.com/uploads/1/3/2/8/132814473/6600412.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/bdb80338-53bf-4f9b-b67b-c93388a7e459/42542378017.pdf
    • https://uploads.strikinglycdn.com/files/65a0468c-3bad-4867-9d21-37708411c681/circuitos_rlc_ejercicios_resueltos.pdf
    • https://uploads.strikinglycdn.com/files/6a8bf434-99c1-48f8-9285-48f96671f996/vtech_manual_cs6829-2.pdf
    • https://uploads.strikinglycdn.com/files/3cb965a3-12f3-4f13-8da2-66a8ff14539a/gta_san_andreas_ahin_yama.pdf
    • https://uploads.strikinglycdn.com/files/9b2dc054-ec15-450e-9a5c-8244873d3319/tonuv.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ba84.bin
557b3e5848e1cdffa2123026ce3ead60465afba3fd466b0581e00a995d2c0b10
pdf-font-stream PDF embedded font (sfnt) at offset 0xBA84 5444 bytes
font_01_sfnt_off0000cce0.bin
4f9ecc4502bcb12595c9e856aa2abc4720e0b243b128d70c2990146437017edd
pdf-font-stream PDF embedded font (sfnt) at offset 0xCCE0 10760 bytes