Malicious PDF — malware analysis report

Static analysis result for SHA-256 0913ab0340503e82…

MALICIOUS

PDF

51.1 KB Created: 2020-08-15 00:28:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 752c21d43d35afb6190cc7388a7a3583 SHA-1: e93352534296cc4340292676672edbabcb483cb0 SHA-256: 0913ab0340503e8226ed71fccc09521195f9a828673bc9d5a152159e4784b5a8
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, with at least one pointing to known malicious redirector infrastructure. The document body text is minimal and appears to be obfuscated or corrupted, but it does contain the primary malicious URL. The ML classifier strongly indicated maliciousness, supporting the heuristic findings.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=b+r+t+f+full+form
    • http://gogube.methowvalleyciderhouse.com/uploads/1/3/0/7/130739664/1189374.pdf
    • http://gijumujad.shahrilfaisal.com/uploads/1/3/1/3/131380600/kepew_xuzomaligitu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0430/8015/5290/files/22061664208.pdf
    • https://cdn.shopify.com/s/files/1/0431/2032/8864/files/51800797568.pdf
    • https://cdn.shopify.com/s/files/1/0428/6542/6598/files/afb_staining_procedure.pdf
    • https://cdn.shopify.com/s/files/1/0439/8612/4958/files/genetics_a_conceptual_approach_4th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0432/4560/0936/files/bupijuguw.pdf
    • https://cdn.shopify.com/s/files/1/0431/3907/2161/files/loneleredaziroluvi.pdf
    • https://cdn.shopify.com/s/files/1/0430/6380/4058/files/6087102611.pdf
    • https://cdn.shopify.com/s/files/1/0434/1720/6946/files/bibatubefufalumirunow.pdf
    • https://cdn.shopify.com/s/files/1/0433/7329/7814/files/18857372167.pdf
    • https://cdn.shopify.com/s/files/1/0434/5066/3073/files/git_add._vs_all.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f3b.bin
811f1d63a30a3965f43a091e10271d78c9551a33e2ee465127ed18ab41fd3a52
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F3B 4576 bytes
font_01_sfnt_off00007eb3.bin
9e4e2e0f41fe4e7d7610045fb3db6259b11828f802034377992d05ed31fac888
pdf-font-stream PDF embedded font (sfnt) at offset 0x7EB3 13940 bytes
font_02_sfnt_off0000aa74.bin
c41fc46809d2260d2d1a821cef6bb00dae560fdbad380da94a93f29d012df54e
pdf-font-stream PDF embedded font (sfnt) at offset 0xAA74 16164 bytes