Malicious PDF — malware analysis report

Static analysis result for SHA-256 02dd2f5bc14c130e…

MALICIOUS

PDF

45.2 KB Created: 2020-08-26 13:49:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5691c9e69b7de0e0b17207c4ee361be5 SHA-1: a373de5eebcce0334af962cd1fcc96f5d777e859 SHA-256: 02dd2f5bc14c130e6e9223f4a0c52f004b3ed1f1b8602d7dee9017d1496763e7
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to a redirector service known for malicious activity. The document body, though partially corrupted, includes the primary malicious URL, suggesting an attempt to direct users to potentially harmful content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=clasificacion+de+angulos+por+su+abertura
    • http://xuvos.launch-studios.com/uploads/1/3/0/7/130775726/lukevularosemo.pdf
    • http://files.soulhealthservices.com.au/uploads/1/3/0/7/130775645/2308874.pdf
    • http://files.christopherjohnsonarted.com/uploads/1/3/0/9/130969241/1443521.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0431/8085/1362/files/88488608687.pdf
    • https://cdn.shopify.com/s/files/1/0429/7709/9935/files/bacterial_attachment_and_biofilm_formation.pdf
    • https://cdn.shopify.com/s/files/1/0435/9749/6477/files/45406134647.pdf
    • https://cdn.shopify.com/s/files/1/0437/0278/0072/files/optical_brighteners_for_plastics.pdf
    • https://cdn.shopify.com/s/files/1/0431/7354/4093/files/gagumezixuvuj.pdf
    • https://cdn.shopify.com/s/files/1/0431/7832/8221/files/kagezukusirikozoduroxeli.pdf
    • https://cdn.shopify.com/s/files/1/0432/8200/6171/files/mologetarawovoxir.pdf
    • https://cdn.shopify.com/s/files/1/0432/9226/2560/files/bidebaxalujapasifejipog.pdf
    • https://cdn.shopify.com/s/files/1/0432/9039/4788/files/sociedad_y_economa_en_el_paleoltico_y_neoltico._la_pintura_rupestre.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063aa.bin
5bf01103174d480aa9c0605c569f7e49e94851cc45310a3819c8273357e3cf11
pdf-font-stream PDF embedded font (sfnt) at offset 0x63AA 2924 bytes
font_01_sfnt_off00006e1f.bin
ac045098b893289a00f0c6186114710c3d7899dc3020c2b2fee9fb8fb1bd9d1b
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E1F 5368 bytes
font_02_sfnt_off0000805f.bin
4416b97deefd3a28264d89553e13dde68d65b6db386da29584e973138f9724a4
pdf-font-stream PDF embedded font (sfnt) at offset 0x805F 11640 bytes