Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3e4b8b31b1b3240…

MALICIOUS

PDF

66.8 KB Created: 2020-11-25 13:08:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: e8c8cb0de1d223306841ffcd31177acd SHA-1: b2c899fd082de15249a05dfb9fc87413e8bb223e SHA-256: f3e4b8b31b1b3240dfd0ab7ba50e21129a8f0a9c70923844a32f27c49493b4a2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic identifying it as a 'PDF_SEO_LINK_FARM'. One of the primary external links, 'https://traffset.ru/wb?keyword=booklet%20layout%20design%20pdf', suggests a lure to a website. ClamAV and ML classifiers also flagged this PDF as malicious, indicating a phishing or trojan-like intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/wb?keyword=booklet%20layout%20design%20pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4425230/normal_5f9dc0cc74498.pdfIn PDF document text
    • https://xiruzukigipimog.weebly.com/uploads/1/3/4/8/134865515/d50a3dd24cbfb1b.pdfIn PDF document text
    • https://sipusojatavajuw.weebly.com/uploads/1/3/4/6/134606658/burafidafoxi.pdfIn PDF document text
    • https://jutulomivepira.weebly.com/uploads/1/3/4/7/134775876/1b9029c0.pdfIn PDF document text
    • https://wajifisawebe.weebly.com/uploads/1/3/4/4/134480175/97954e5b49e.pdfIn PDF document text
    • https://foxevavudutis.weebly.com/uploads/1/3/4/3/134380199/dfddc8dd776cc16.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/da947a73-c634-4a12-9801-4e0018e332d8/kewevur.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/42dd2de7-300c-4ce6-ab6c-9ba9d7e3e780/nordictrack_treadmill_repair_parts.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c7422990-b56f-46de-b6b4-30b150feecbc/93237208249.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2501010e-37bb-4bef-a9b6-b9b8eb6734ec/komojogaroxufapi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/09fbbb8e-9649-4be9-b512-0e3310cbccfc/30502651668.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d4e25eeb-a2d2-417c-8828-030ae64f100c/cells_concept_map_answer_key.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c667.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC667 5328 bytes
SHA-256: d9147798445cb9af0d4116dfb29283f32ab268f92f74c72f0fd251f8a381c5f5
font_01_sfnt_off0000d8b5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD8B5 11196 bytes
SHA-256: d4c3d400e9984ed9281846b77d59b464d48de67558c23a024c44f4455ee7f4f5