Malicious PDF — malware analysis report

Static analysis result for SHA-256 dfe7a20c5fbbe96e…

MALICIOUS

PDF

66.7 KB Created: 2020-12-11 16:15:39 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-05
MD5: 5f611b1fc9bec2923bb92f7c012ec4cd SHA-1: 1d7d99956fb9684d64a6e797bd7ac7ab58c0f90e SHA-256: dfe7a20c5fbbe96e270737188046ae8ddc4c367a7238d928dd5706cbab8c83c9
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing indicating it links to known malicious redirector infrastructure. The embedded URL 'https://gettraff.ru/123?utm_term=black+ops+zombies+apk+free' is associated with this malicious activity. ClamAV also detected the file as 'Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0', further supporting its malicious nature. The presence of a 'download button' heuristic suggests a lure to trick the user into clicking the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/123?utm_term=black+ops+zombies+apk+free In PDF document text
    • https://cdn-cms.f-static.net/uploads/4453328/normal_5fa629e4a6ee9.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4426682/normal_5fc94a4321a43.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4404750/normal_5fd33233a692c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://static1.squarespace.com/static/5fc1015360f2895dc1e86a3c/t/5fc59ce34e98326c02d26939/1606786276226/banimo.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe0cf4f81c9a2a0c699ada/1606290677179/nefipum.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc1d0d6bd14ff0dd2a325bf/t/5fcc1eb15177ea328cb199e9/1607212722706/gelogipigojek.pdfIn PDF document text
    • https://s3.amazonaws.com/zetituri/gonelirurixenipaxepatun.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e8cf564a-218c-44a8-8167-714815393ad6/26375960377.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0d2c9b9a-2578-4928-a257-3e3499c1fce7/best_paleo_cookbook_2020.pdfIn PDF document text
    • https://s3.amazonaws.com/kefiperizonofu/graham_norton_show_australian_tv_guide.pdfIn PDF document text
    • https://s3.amazonaws.com/risisipajole/similiwoxerutiroka.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c47c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC47C 5464 bytes
SHA-256: 2ad3c1df704b705f6333f4faff1cd698e982517296e6bbf578257165a78d9b5e
font_01_sfnt_off0000d707.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD707 11656 bytes
SHA-256: dc36e7da183b604bf2aa0dad0e558aa50f85d8f0481f70b127bd062c5b9368e2