Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d5606e37b3c1d69…

MALICIOUS

PDF

61.6 KB Created: 2020-07-13 18:56:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a979d1c0a14257b07b2b8bfe546cc7c6 SHA-1: d66c061100a3affc455b0186f67dc5a8ead2eb1b SHA-256: 0d5606e37b3c1d6996d106ee8aa733ac481d0cbb28f996065ac462375e0f0ee4
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, with one critical heuristic identifying it as a link farm pointing to potentially malicious redirectors. The ML classifier also strongly flagged this PDF as malicious. The primary attack pattern involves directing users to external sites, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=rigid%20pavement%20books%20pdf
    • http://files.breathewithlauren.com/uploads/1/3/1/4/131437351/424db3.pdf
    • http://files.businessdesignservices.com/uploads/1/3/0/7/130776646/livepoxozoz-jazevivorujomi-wimoboxoxa-fuxaf.pdf
    • http://files.cedarspringschristianchurch.org/uploads/1/3/2/6/132682883/f9b8d04f9aa5.pdf
    • http://files.maplerunfriends.com/uploads/1/3/2/7/132710630/kubaguzeziku_xuwemorefep.pdf
    • http://files.martazaremba.com/uploads/1/3/2/6/132681824/218139.pdf
    • http://files.lifesurprisesyou.com/uploads/1/3/2/6/132681931/xegozanozeluzupisol.pdf
    • http://files.heathenmist.com/uploads/1/3/1/3/131397955/zerelipokifimej_jilunujamagi_mutezerobezofa_vafusimi.pdf
    • http://files.newleaforganizingllc.com/uploads/1/3/1/8/131857071/6418065.pdf
    • http://files.serenavitabirth.com/uploads/1/3/2/8/132814567/2685752.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://kojesurobiza.files.wordpress.com/2020/06/vipuniluvimupupaguf.pdf
    • https://davotivepu.files.wordpress.com/2020/06/10285258280.pdf
    • https://wuwelenimat.files.wordpress.com/2020/06/bepulesazatezizu.pdf
    • https://guvadade.files.wordpress.com/2020/06/28609280792.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/kemulubu.pdf
    • https://cdn.shopify.com/s/files/1/0433/9200/8357/files/timude.pdf
    • https://cdn.shopify.com/s/files/1/0432/0998/2107/files/zesegibupaxixabazupog.pdf
    • https://cdn.shopify.com/s/files/1/0432/8413/6086/files/ponuzarebuvak.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/jotinu.pdf
    • https://cdn.shopify.com/s/files/1/0428/0814/8127/files/nupitabipi.pdf
    • https://cdn.shopify.com/s/files/1/0433/0032/3478/files/loxalodutuzinajunofapa.pdf
    • https://cdn.shopify.com/s/files/1/0432/4071/8496/files/92544856220.pdf
    • https://cdn.shopify.com/s/files/1/0432/1175/1579/files/12023330991.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b2dd.bin
2c4eb521a9eb5c962c7a1e75f99b1b416c9e60a9c31950723fb8ddbb5289f29b
pdf-font-stream PDF embedded font (sfnt) at offset 0xB2DD 5292 bytes
font_01_sfnt_off0000c4d9.bin
469bc6770aff0c72d33e7e24114d3c057d46dc2af051125a0e215b3fc66ebca8
pdf-font-stream PDF embedded font (sfnt) at offset 0xC4D9 10540 bytes