Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed500033cf7426b8…

MALICIOUS

PDF

39.9 KB Created: 2020-11-07 07:46:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 94c070914f98b279040a9403731c277c SHA-1: c02051dd7b3b93ccdb7e12c6e42094c4e88bfb2c SHA-256: ed500033cf7426b823be1e3f33d6188096544cafadc4ec329cedeb8b855599ba
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document is designed as a lure, presenting itself as an answer key to encourage clicks on embedded links. The primary malicious URL, https://trafffe.ru/aws?keyword=hardy+weinberg+problem+set+dragon+answer+key, is part of a link farm, indicating a likely SEO manipulation or traffic redirection scheme. While no scripts were explicitly extracted, the PDF structure and embedded links suggest potential for exploitation or further redirection, aligning with common phishing and SEO spam tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/aws?keyword=hardy+weinberg+problem+set+dragon+answer+key
    • https://mefomenixa.weebly.com/uploads/1/3/4/2/134235772/tesiwuganukix-mirowepitutano-fedotosisu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/poresi/cuisinart_deluxe_11_food_processor_manual.pdf
    • https://s3.amazonaws.com/widofafane/81322610277.pdf
    • https://uploads.strikinglycdn.com/files/72fc4ec6-2a03-4439-8122-001363c34cd7/jakozukusoteluta.pdf
    • https://s3.amazonaws.com/bitizopovopaso/wipofuwexowot.pdf
    • https://uploads.strikinglycdn.com/files/0bb390c3-5686-4652-975a-b29a941bf98e/25346635562.pdf
    • https://uploads.strikinglycdn.com/files/3b496f4d-4334-404f-bdc8-f6d4c898df27/fukawufi.pdf
    • https://s3.amazonaws.com/baxegezivumi/malaria_caso_clinico.pdf
    • https://uploads.strikinglycdn.com/files/3615541b-fa2d-435d-be6e-0ee9ae9705e9/wight_dd_beyond.pdf
    • https://uploads.strikinglycdn.com/files/a6c0f0c8-ceed-4a2c-86bc-bdfc7ae2402e/ninepovopaga.pdf
    • https://uploads.strikinglycdn.com/files/d4e9c93d-9c09-455a-8c11-2fd91f8d0107/nissan_370z_roadster.pdf
    • https://uploads.strikinglycdn.com/files/2c419e8a-4bf4-415e-b6cb-30350fd5cbde/18849913194.pdf
    • https://uploads.strikinglycdn.com/files/594cd1e7-ae4f-45f8-b918-b74945a76ab6/8262799145.pdf
    • https://uploads.strikinglycdn.com/files/52aca14f-2e44-4e49-9262-7d425c1bfdd8/77646781721.pdf
    • https://uploads.strikinglycdn.com/files/8d864bd6-d345-423e-8fa1-c145f87e2458/writing_hypothesis_ppt.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005c26.bin
7b780445c04e7db9e36f60ec8be33a5bb7966feda6541bb0853aee0299738f5d
pdf-font-stream PDF embedded font (sfnt) at offset 0x5C26 5640 bytes
font_01_sfnt_off00006f58.bin
657abca2aeb969cddb4ce5637a142ce191d4f4b58eb55b34108d074a5b25645c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F58 10276 bytes