Malicious PDF — malware analysis report

Static analysis result for SHA-256 06db7819215ec571…

MALICIOUS

PDF

44.0 KB Created: 2020-08-21 20:08:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4c6e66c28d3a0da611de195479e7ad0e SHA-1: a4d2a3124d52c19abf9f7a49d2a9c125d4032f0a SHA-256: 06db7819215ec5716853ebd20049b7ec18dc4510473f93cc4ecd91c7bad7e5ab
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to a redirector service known for malicious activity. The document body, though heavily obfuscated, contains the URL that triggers the redirector. This suggests an attempt to lead the user to malicious content, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=medical+certificate+format+for+maternity+leave+extension
    • http://liganudeb.placentaoc.com/uploads/1/3/1/3/131380213/kejivopusag-zonilugonobij.pdf
    • http://vazelo.paramountbuilders.co.uk/uploads/1/3/1/3/131383483/desaxokotemo-balopojumi-pokipurarokaj.pdf
    • http://files.phoschol.com/uploads/1/3/0/9/130969140/kuzesile.pdf
    • http://files.ajukmapparel4.com/uploads/1/3/1/4/131482823/fe3fb682.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0436/4579/6512/files/how_do_i_change_my_minecraft_launcher.pdf
    • https://cdn.shopify.com/s/files/1/0431/2937/2836/files/98599947943.pdf
    • https://cdn.shopify.com/s/files/1/0435/3300/9047/files/gettysburg_address_quiz.pdf
    • https://cdn.shopify.com/s/files/1/0433/7732/8278/files/core_java_black_book_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/6214/0840/files/37440674177.pdf
    • https://cdn.shopify.com/s/files/1/0431/3317/3927/files/bhagavad_gita_chapter_1_in_marathi.pdf
    • https://cdn.shopify.com/s/files/1/0432/2990/5058/files/american_english_file_4_second_edition.pdf
    • https://cdn.shopify.com/s/files/1/0434/4594/4481/files/soxhlet_extraction_lab_report.pdf
    • https://cdn.shopify.com/s/files/1/0429/9702/2879/files/what_is_a_discord_webhook.pdf
    • https://cdn.shopify.com/s/files/1/0429/2981/5711/files/kokibolupakugata.pdf
    • https://cdn.shopify.com/s/files/1/0430/4296/3613/files/60738567899.pdf
    • https://cdn.shopify.com/s/files/1/0434/1307/8168/files/24880601592.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006e4b.bin
7c86d4872bd03634865dd6fb186fe64565fe8d050a5ec0055a5cef94b92bdeb9
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E4B 5400 bytes
font_01_sfnt_off000080a3.bin
2bf30e81e1dae30d54bd693682a5ae963b85bad84a673b01844b9af8075786a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x80A3 9988 bytes