Malicious PDF — malware analysis report

Static analysis result for SHA-256 0448d95db094812e…

MALICIOUS

PDF

41.3 KB Created: 2020-09-15 01:14:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 04d258af148c0e09fb357c4ffb2abb93 SHA-1: a486bd366d2e5233546529fa499cf3f466ac34ec SHA-256: 0448d95db094812e392376d5929ac938d4a26fe2e8949c9b9a6c0827abdb1021
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF was flagged as malicious due to a high ML score and the presence of a link farm containing a known malicious redirector. The document body contains numerous embedded URLs, suggesting a phishing or malware distribution attempt. The primary malicious IOC is the redirector URL, which likely leads to a malicious payload or phishing page.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=the%20giver%20chapter%20response%20answer%20key%20joy%20sexton
    • http://files.forzarealty.com/uploads/1/3/0/7/130775747/252d4ea67de14c7.pdf
    • http://files.marinashay.com/uploads/1/3/1/4/131406518/440cbd99bb939f.pdf
    • http://sumafebu.ksferguson.net/uploads/1/3/0/9/130969808/4746226.pdf
    • http://najivesu.berlinproject.donaldunger.com/uploads/1/3/2/8/132814239/2674265.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/866690_fc953c6b67e9409db3938f320a87dbf6.pdf
    • https://static.usrfiles.com/ugd/1b8612_6c55272fc2ed47f2814e6d93d13d1031.pdf
    • https://static.usrfiles.com/ugd/62e2c1_a3f5f8dbbaab45bb89b4a90ee6bec7e7.pdf
    • https://static.usrfiles.com/ugd/b8c837_697aaf178e0b4b4287b4993b826fa0c9.pdf
    • https://static.usrfiles.com/ugd/d4579c_f6428b6d17114996ae3b2eba0f4ecc85.pdf
    • https://static.usrfiles.com/ugd/1ee69b_e743e959704f48d482f822dd61e2c28e.pdf
    • https://static.usrfiles.com/ugd/99b222_eaa3abeb8655433fa78ea64ba5b79355.pdf
    • https://static.usrfiles.com/ugd/76de1a_087d67b8ca544a53ad2cdab8fe6626c7.pdf
    • https://static.usrfiles.com/ugd/9ced5d_083b07a3abcf40f5a0f873096f50e433.pdf
    • https://static.usrfiles.com/ugd/c8d394_382e77af250f4593aac5ff59fb5d22de.pdf
    • https://static.usrfiles.com/ugd/7e0eb0_7bca0c089f8b4dedb83a07b55848a1c5.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000600a.bin
93c2f24255963a0924257675204ec6dc66b6b297638434aa5fa763b942bb57e7
pdf-font-stream PDF embedded font (sfnt) at offset 0x600A 5572 bytes
font_01_sfnt_off00007323.bin
b2de72f92c95f6d931940ee883b1da2223548a7216c4667cbef55b764787cec9
pdf-font-stream PDF embedded font (sfnt) at offset 0x7323 10972 bytes