Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea1ecd3ede783616…

MALICIOUS

PDF

87.9 KB Created: 2020-12-28 01:50:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8b76981081fb0c83b9a54034c42c3056 SHA-1: 11c100c5cdba39678a50dab8fb812d73553cff4b SHA-256: ea1ecd3ede783616c8d0f7db62e58c7d4d3f2e24dd992681ee8b897e67e625bf
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains a large number of external links, including one pointing to 'traffset.ru', suggesting a phishing or SEO spam campaign. The presence of embedded links and the PDF structure strongly suggest it's designed to redirect users to potentially harmful websites, possibly to deliver further malware or conduct phishing attacks.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/123?utm_term=windows+media+center+program+guide+no+data+available
    • https://cdn-cms.f-static.net/uploads/4365626/normal_5faee6d323530.pdf
    • https://kedifekutijita.weebly.com/uploads/1/3/4/7/134713117/mirip_fokunudiwigipi_kidusip.pdf
    • https://cdn-cms.f-static.net/uploads/4465403/normal_5fe8e5cf83ee1.pdf
    • https://static.s123-cdn-static.com/uploads/4385417/normal_5fe4b9d6569db.pdf
    • https://cdn-cms.f-static.net/uploads/4379234/normal_5f978e4552c5f.pdf
    • https://static.s123-cdn-static.com/uploads/4413228/normal_5fe2a430cf267.pdf
    • https://cdn-cms.f-static.net/uploads/4465907/normal_5fbab4c20dc38.pdf
    • https://cdn.sqhk.co/luvuxokam/liiigx7/stadia_review_uk.pdf
    • https://static.s123-cdn-static.com/uploads/4482009/normal_5fc591ab1c392.pdf
    • https://pizeposinejuxow.weebly.com/uploads/1/3/2/6/132695365/b8240955eca657.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/zamuriza/bleacher_report_consensus_picks_week_3.pdf
    • https://s3.amazonaws.com/ropuba/centimeter_ruler_actual_size.pdf
    • https://s3.amazonaws.com/metakibeme/11555349815.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e289.bin
a36ef4d7c90461876971a2f5e8ea748eb27417b01e6bd0d7a145bca194beeb92
pdf-font-stream PDF embedded font (sfnt) at offset 0xE289 12912 bytes
font_01_sfnt_off00010cd0.bin
5cbbfe7f838033a667fc6701b5b5093bb24364e33f4bb168d2ac7ffc5be44f59
pdf-font-stream PDF embedded font (sfnt) at offset 0x10CD0 5580 bytes
font_02_sfnt_off00011fc3.bin
bf7755e9d2ac0b8bae805e6bca4b6dfb109fa4c915bac3ba0c4c58a04a78b3b3
pdf-font-stream PDF embedded font (sfnt) at offset 0x11FC3 10552 bytes
font_03_sfnt_off000143e3.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x143E3 4324 bytes