Malicious PDF — malware analysis report

Static analysis result for SHA-256 0844d0acd76ecc5a…

MALICIOUS

PDF

100.5 KB Created: 2020-08-31 08:20:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9e4af57c132f4f6df097574454bade4e SHA-1: fc06bbae2a81591eab9accbce3eb592df6c2c7d0 SHA-256: 0844d0acd76ecc5ace21467d8ea390a9850b4bb8cfd5af6644dde7a78d162ace
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, disguised as a search query for popular media. The ML classifier also flagged this PDF as malicious. The embedded URL is the primary indicator of malicious intent, likely leading to a phishing or malware download site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=lost+season+1+episode+1+english+subtitles
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102Hussain
    • http://smc.org.inhttp://smc.org.in
    • http://www.indictrans.org
    • http://www.opentle.org
    • https://cdn.shopify.com/s/files/1/0432/9390/0968/files/introduction_to_automata_theory_languages_and_computation_2nd_edition.pdf
    • https://cdn.shopify.com/s/files/1/0432/2987/2292/files/protective_relays.pdf
    • https://cdn.shopify.com/s/files/1/0434/5410/3713/files/79362296225.pdf
    • https://cdn.shopify.com/s/files/1/0432/7348/6496/files/jamestown_colony_worksheets.pdf
    • https://cdn.shopify.com/s/files/1/0431/4116/9303/files/itr_2_assessment_year_2018-_19.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/69296453687.pdf
    • https://cdn.shopify.com/s/files/1/0432/1394/7048/files/lowejoterekavaxilosadaj.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/60527157158.pdf
    • https://cdn.shopify.com/s/files/1/0429/1336/6182/files/gutachten_jura_zeitform.pdf
    • https://cdn.shopify.com/s/files/1/0429/6117/4684/files/whirlpool_oven_accubake_system_self_cleaning_manual.pdf
    • https://cdn.shopify.com/s/files/1/0428/4514/3207/files/pilonepoxefenobusuvepap.pdf
    • https://cdn.shopify.com/s/files/1/0428/9495/0556/files/luvoxoli.pdf
    • https://cdn.shopify.com/s/files/1/0434/3712/9895/files/inches_to_mm_conversion_chart.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • https://gitlab.com/smc/meera/blob/master/COPYING
    • http://sinhala.sourceforge.net/
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITS
    • http://www.gnu.org/licenses/gpl-2.0.html
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 15

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_016_off00014f82.bin
41106fe9a07ceeb1833557e0ab2cfbd1aaa01bb8b874b05d5e7cc5f1a8674fa4
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x14F82 18892 bytes
font_00_sfnt_off000075e6.bin
e59037b55eb65fa6455cf1c6287e33a9d16be46809afb7af2e33fa14b570a7d3
pdf-font-stream PDF embedded font (sfnt) at offset 0x75E6 7916 bytes
font_01_sfnt_off00008a46.bin
1d890cbc49c86b194b6bea92bfd272c23f59aa3734dae7befebffe896f6f634c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A46 4032 bytes
font_02_sfnt_off000098b6.bin
4894882b773af7cc949005ac286608829de4a7c02f72ef038b4aa7a943b8f7a1
pdf-font-stream PDF embedded font (sfnt) at offset 0x98B6 5256 bytes
font_03_sfnt_off0000aa8c.bin
dbaab8dcf32bfe64cb008f34eb54f5316f62236e8dffe3de49b44225404383a5
pdf-font-stream PDF embedded font (sfnt) at offset 0xAA8C 2656 bytes
font_04_sfnt_off0000b58e.bin
119132d4d86df12b64aacef50f1aeac69cc60fdd8dbe27b6e2ceb22654f0acbc
pdf-font-stream PDF embedded font (sfnt) at offset 0xB58E 4140 bytes
font_05_sfnt_off0000c2ab.bin
1b68eb0745f369bd9f805b89718582bd6ebaf917deeaaae5095027b3f32dc7b8
pdf-font-stream PDF embedded font (sfnt) at offset 0xC2AB 3048 bytes
font_06_sfnt_off0000ceb8.bin
c42118b51b061dffbc196cd4866a2cf76d9f31ae9d0a8f6c06e6ad224a677b24
pdf-font-stream PDF embedded font (sfnt) at offset 0xCEB8 2328 bytes
font_07_sfnt_off0000d96f.bin
d07a9fdf75b1e191e7a1ea25e2941b9f689ff98e7e435169aef8b5fb7be41b17
pdf-font-stream PDF embedded font (sfnt) at offset 0xD96F 2604 bytes
font_08_sfnt_off0000e447.bin
5b8e8035f8940535bfb5f3d78de7d5c45dbc51c905faa5d9788b8fc152e96872
pdf-font-stream PDF embedded font (sfnt) at offset 0xE447 3840 bytes
font_09_sfnt_off0000f256.bin
806d12f4c18e044784d20764d58024893796e88f204c306662924b3e907cbcac
pdf-font-stream PDF embedded font (sfnt) at offset 0xF256 2108 bytes
font_10_sfnt_off0000fc2f.bin
87016e8933cc862d1d188edfbee698abcff8178ed3d6b510b61737ee02f60284
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC2F 4336 bytes
font_11_sfnt_off000109cf.bin
be38186c9256ba0e64b07d34cca2e63b176d3ffd182ae4667a642b503e748fe0
pdf-font-stream PDF embedded font (sfnt) at offset 0x109CF 6148 bytes
font_12_sfnt_off000119b9.bin
6f004a60fb4cde98711cc885aa2c7e5c7de4ae51b57ca85dddd5b05dcad218ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x119B9 17636 bytes
font_14_sfnt_off00016ede.bin
ecf51c2dbb9281b20c5dc3daf9ad1c9b9cc7ec56331f29427b924fb34bf6c063
pdf-font-stream PDF embedded font (sfnt) at offset 0x16EDE 3536 bytes