Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3ca19534408a520…

MALICIOUS

PDF

95.7 KB Created: 2020-11-25 00:53:32 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b9015d6ef3b8343cf9e09a60ae059602 SHA-1: fffad824125deba709eafcb77dd6a98b74cff2b4 SHA-256: e3ca19534408a520d570dca5b486ce5fef3407e87394135df7de6858585236ad
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for linking to known malicious redirector infrastructure, specifically 'https://gettraff.ru/aws?utm_term=cytosol+definition+pdf'. ClamAV also detected it as Pdf.Phishing.Trojan. The ML classifier strongly flagged this PDF as malicious. While no scripts were extracted, the embedded URL and the nature of the heuristics indicate a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/aws?utm_term=cytosol+definition+pdf
    • https://cdn-cms.f-static.net/uploads/4427538/normal_5fa0867c01a7d.pdf
    • https://cdn-cms.f-static.net/uploads/4387419/normal_5f8d7bd23f27c.pdf
    • https://cdn-cms.f-static.net/uploads/4380382/normal_5fa2dfb8029a7.pdf
    • https://cdn-cms.f-static.net/uploads/4416665/normal_5f97af43d0946.pdf
    • https://cdn-cms.f-static.net/uploads/4474746/normal_5fa8aa8a82512.pdf
    • https://cdn-cms.f-static.net/uploads/4445889/normal_5fbc39284a3c4.pdf
    • https://cdn-cms.f-static.net/uploads/4385030/normal_5fa1de377e84f.pdf
    • https://cdn-cms.f-static.net/uploads/4371806/normal_5f9c2d139c543.pdf
    • https://cdn-cms.f-static.net/uploads/4464070/normal_5fa223860ed3d.pdf
    • https://cdn-cms.f-static.net/uploads/4422145/normal_5fad81b80eac5.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/muxegeza/pelewozumamovuloliwu.pdf
    • https://uploads.strikinglycdn.com/files/256b6c60-9d98-441d-b296-749aa060620d/understanding_art_11th_edition_ebook.pdf
    • https://s3.amazonaws.com/fomaralunex/pneumonia_severity_index_espaol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001245a.bin
c1855c759b9d4a37cc606ed6eb5977e6e1e710900e7d7003b1c725322b7f7f4d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1245A 4736 bytes
font_01_sfnt_off00013499.bin
f90b2b33dbb1f069b5c475dc211af448c588532c5d2d4ee93c4818aec9aca0f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x13499 12336 bytes
font_02_sfnt_off00015cf3.bin
3c904e35a177b6dbb92fb4a72ebcf70f4514e6e9eb8bdc0a540163946dcb2d80
pdf-font-stream PDF embedded font (sfnt) at offset 0x15CF3 16084 bytes