Malicious PDF — malware analysis report

Static analysis result for SHA-256 e068588f88582e29…

MALICIOUS

PDF

107.7 KB Created: 2020-11-23 16:40:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-26
MD5: c4a180c862939e1950cd862e84eb23ab SHA-1: 304a04a917b953ccf3a597ba5d3e8f4b858a4f7f SHA-256: e068588f88582e2935bd9c30cbba8d01e893d2d13a559d5f227b5649d99b0ac9
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by multiple heuristics and a machine learning classifier, indicating it likely serves as a phishing or malware distribution lure. It contains numerous embedded links, including one pointing to known malicious redirector infrastructure (ggtraff.ru), and another to a PDF link farm (zosetujisux.weebly.com). The document body, though heavily obfuscated, contains text related to age of consent, suggesting a deceptive lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/123?utm_term=mexico+age+of+consent+is+12 In PDF document text
    • https://zosetujisux.weebly.com/uploads/1/3/4/2/134266291/02d37.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451028/normal_5faae2b861468.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379849/normal_5fa331b2e8e76.pdfIn PDF document text
    • https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/kezupukono.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370768/normal_5f8fd91fde61b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417039/normal_5f99d7b12350c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/4d3502dd-9e2a-4cb7-94e6-d15b6b0112ac/gemini_7208_car_alarm_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a41e59b-390c-4ac6-bd01-374e4a0bdf5f/usb_2.0_crw_driver_windows_7_dell.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e4e0c47d-07f8-42d0-b248-33ac9936a78f/madea27s_big_happy_family_full_movie_free_online.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1a1f5662-63d6-49fd-9a5a-3495ccb9284c/babytorrent_proxy_site.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1d6be7f2-35a2-48a9-a980-49b86ebeb449/taxotak.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7a8a613d-9cc1-41eb-b2ce-6928478987ec/jijavizakumizinet.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e032f3c0-e8e8-48cf-be14-18effafce096/saC49F_salim_1_izle_full.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00016628.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16628 5180 bytes
SHA-256: 4e137615f8837c0f550d0fafe322405487d048ce2952ec13512a350f375f047a
font_01_sfnt_off00017800.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17800 13076 bytes
SHA-256: 8e4e14b8a5287c83281bee967a7d864badb22806dc20769052daad0956c7e950