Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d956168a45fdc7c…

MALICIOUS

PDF

35.1 KB Created: 2020-09-17 19:18:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0405a292436e176e012d8c38fd8359e4 SHA-1: 34ca8bddfe3d49cadfb07c36a2e582a3d765dabd SHA-256: 0d956168a45fdc7cb672a950db74f940e7b81a13ee12e2960a29870a659925e6
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with one specifically pointing to a known malicious redirector infrastructure. The document body, though partially corrupted, contains text that appears to be a lure related to 'pba 2k14 apk' and includes the malicious URL. The presence of a link farm and the ML classifier's high confidence score further support the malicious nature of this document.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=pba+2k14+apk
    • http://zavoponok.linwoodfire.com/uploads/1/3/0/8/130873782/bimisevekujumasaneto.pdf
    • http://xapeve.marissaoneil.com/uploads/1/3/1/4/131438562/4902397.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0437/2958/4282/files/california_child_support_calculator_user_guide.pdf
    • https://cdn.shopify.com/s/files/1/0429/3161/7945/files/interface_contract_document_template.pdf
    • https://cdn.shopify.com/s/files/1/0431/5981/4306/files/pl_sql_interview_questions_and_answers_for_3_experience.pdf
    • https://cdn.shopify.com/s/files/1/0432/3724/5085/files/hyperbole_and_a_half.pdf
    • https://cdn.shopify.com/s/files/1/0437/4760/6679/files/22839807651.pdf
    • https://0b4d7da4-9710-4552-abe8-61d790163cbc.filesusr.com/ugd/96564c_d75108c9323e4b09949c7c7f2f745f5d.pdf?index=true
    • https://34f7060d-3ab7-457d-8d2b-0c5aa3c0775d.filesusr.com/ugd/d8966e_b7641a46b1b1474b9e65a4ca3c6acdfa.pdf?index=true
    • https://c23404da-0451-4b7f-80e6-a1a8e139e0cd.filesusr.com/ugd/ea9bdf_a335805a2d684b54bd418b730ab5dedb.pdf?index=true
    • https://f9b81543-79bd-4868-8952-af14d78960d2.filesusr.com/ugd/b926a8_e3d504e95f904b3fb1159c0a9e1a69b7.pdf?index=true
    • https://c61b34b9-558d-416d-8d3a-de9cc65e25c0.filesusr.com/ugd/bf0735_21291315200a4ee097903de360ff9074.pdf?index=true
    • https://9de8ad10-836d-4523-ade9-18d1975f29d6.filesusr.com/ugd/c8683e_ea0af676621e4bf891cc249a5d4a42af.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004c89.bin
7c7dcfede1a0719055366569748797cbe6fff760dcb8d6872f48967b8e71edfb
pdf-font-stream PDF embedded font (sfnt) at offset 0x4C89 4984 bytes
font_01_sfnt_off00005d9f.bin
c0d8919fb69a09be7347b5c8231b838efc88a5c094abe14206bcc49e6e2ce610
pdf-font-stream PDF embedded font (sfnt) at offset 0x5D9F 10080 bytes