Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef9ecef570670aee…

MALICIOUS

PDF

48.5 KB Created: 2020-11-07 01:22:45 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2f065fb586863ae949c7724fc20d82a3 SHA-1: 1854a9937542c902f708ae0c34f60949f17c843b SHA-256: ef9ecef570670aee63aef57217ff02bdd0ebcf45332986869d8aa0a0516a8886
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are to PDF files hosted on various platforms, suggesting a link farm or SEO manipulation tactic. One of the embedded URLs, 'https://traffnew.ru/aws?keyword=eve+online+ore+compression+calculator', is directly associated with the document's content and likely serves as the primary lure. The ML classifier strongly indicated maliciousness, and the PDF structure with numerous external links aligns with techniques used to drive traffic or distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/aws?keyword=eve+online+ore+compression+calculator
    • https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/powukiravoxon-karov-jekilijo-varubexineda.pdf
    • https://wavutokemik.weebly.com/uploads/1/3/4/3/134309613/wataw.pdf
    • https://fulafokowezoje.weebly.com/uploads/1/3/4/3/134384829/nijabixotolar.pdf
    • https://jokonufukitis.weebly.com/uploads/1/3/4/3/134399540/sitowetugigev.pdf
    • http://www.opentle.org
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://mutozofe.files.wordpress.com/2020/11/67728004733.pdf
    • https://s3.amazonaws.com/pisedij/39778632509.pdf
    • https://pufewureda.files.wordpress.com/2020/11/fimasu.pdf
    • https://juvolubabeb.files.wordpress.com/2020/11/isuzu_4hk1_engine_manual.pdf
    • https://uploads.strikinglycdn.com/files/234d2a3b-8a61-4d42-896a-afc096be1b5a/the_american_wedding_guide.pdf
    • https://s3.amazonaws.com/kavitokolezub/92216894316.pdf
    • https://s3.amazonaws.com/subud/comic_characters_in_pride_and_prejudice.pdf
    • https://s3.amazonaws.com/pazifetanegapu/jonapukabipoga.pdf
    • https://uploads.strikinglycdn.com/files/ab88dfd1-1e5d-423a-9182-ba2ec8ce94b0/botanica_forestal_libro.pdf
    • https://fefitaw.files.wordpress.com/2020/11/64939725781.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://www.gnu.org/licenses/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00006c19.bin
866457c3de3581e853464ace1a7c9a9385c2e2c46dcf3e9fee2154b3c80e5a33
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6C19 12972 bytes
font_00_sfnt_off00005adf.bin
a3c2fe559a4f4346b517f213d98eee558efea59c6a93b337070d50ade4fde54e
pdf-font-stream PDF embedded font (sfnt) at offset 0x5ADF 5096 bytes
font_02_sfnt_off000090bd.bin
b8d207e46774bb49e61c4f20ed3dbbe1485c9e7e47f77b5af16f346939ba4fc6
pdf-font-stream PDF embedded font (sfnt) at offset 0x90BD 10580 bytes