Malicious PDF — malware analysis report

Static analysis result for SHA-256 03c96071f3c25794…

MALICIOUS

PDF

70.5 KB Created: 2020-12-18 05:28:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3776a64d56592f07d4e309a9d016b4fb SHA-1: 562177b64e28ef182c865121f6602c9b743aa66f SHA-256: 03c96071f3c25794d7429330589fdbbbe93bc6da34235284016984d0d7a34210
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs, with a critical heuristic firing for a malicious redirector link. The presence of a PDF link farm suggests an attempt to manipulate search engine results or distribute malicious content. While no scripts were directly extracted, the nature of the embedded links and the ML classification indicate a malicious intent to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffmen.ru/123?utm_term=trans+texas+tire
    • https://zawasofolebu.weebly.com/uploads/1/3/4/9/134902788/206e5c97fbb6d9a.pdf
    • https://sujuwezel.weebly.com/uploads/1/3/4/4/134486010/dejojalumesamuxiso.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/4fb9acfe-fdf2-4f1f-a8a1-3008b0f0ad46/xajinarobibifojegupazuz.pdf
    • https://uploads.strikinglycdn.com/files/71835a75-aa25-40a5-afba-30007bbc3043/11175407029.pdf
    • https://uploads.strikinglycdn.com/files/475efbd8-4be4-4836-b803-c81411bb00e8/wavuzag.pdf
    • https://s3.amazonaws.com/pazifetanegapu/25850959774.pdf
    • https://uploads.strikinglycdn.com/files/0ae0108e-f802-46fa-a91a-a1b7a0af2ae2/88316140134.pdf
    • https://uploads.strikinglycdn.com/files/904a063f-6e3a-460d-9991-247cb47dc147/super_smash_flash_2_mods_sonic_free.pdf
    • https://static1.squarespace.com/static/5fc3b7d50a2757459bf48cbe/t/5fd1446a13fdce15e7be6e46/1607550059461/54435855281.pdf
    • https://uploads.strikinglycdn.com/files/d2cd6a64-9153-4e02-93b6-8afb645c5596/labalirokefudakumetowato.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cb88.bin
6557d0f62d8dc9443777060f3bb7603492bdd648b390532a2d588ab417e49f8f
pdf-font-stream PDF embedded font (sfnt) at offset 0xCB88 4340 bytes
font_01_sfnt_off0000da36.bin
06490433570e1fc3f40f1045bc5b483e454e6251922dc89e3da91251fa15d46b
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA36 10860 bytes
font_02_sfnt_off0000ff35.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF35 4324 bytes