Malicious PDF — malware analysis report

Static analysis result for SHA-256 10fa27316d67841e…

MALICIOUS

PDF

71.7 KB Created: 2020-09-06 04:14:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bcae61ffa5e0ce4abfe486ca45d4c7e5 SHA-1: 394fde3d9d2164571c15c8b5ef5817c67062c497 SHA-256: 10fa27316d67841e738003e72ebda5dd91ee2b8a429246e045fe00ed85339a88
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links that redirect to malicious infrastructure, specifically a URL designed to lure users with the promise of 'Bollywood movies 2017- 18 hd'. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' confirms the malicious nature of the redirector. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to drive traffic to malicious content, likely as part of a phishing or scam campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/pify?keyword=bollywood+movies+2017-+18++hd
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/1df9ea_47110df9980c43b6924104ab102a78ec.pdf
    • https://static.usrfiles.com/ugd/fafc38_865135c1e05e470ca95906d218d315f4.pdf
    • https://static.usrfiles.com/ugd/7ef0dc_a02aea551c614e9abc3765c09e8a40c4.pdf
    • https://static.usrfiles.com/ugd/536122_b92b59a961a141ea9c08c33975b977e3.pdf
    • https://static.usrfiles.com/ugd/eaf48f_d38c28f2be364e3685e7f7da8dcf53b7.pdf
    • https://static.usrfiles.com/ugd/4dd980_1583d845589749f48d077bec7bc4da28.pdf
    • https://static.usrfiles.com/ugd/3fb742_87e451879f054692a8c7484254c94b7f.pdf
    • https://static.usrfiles.com/ugd/cc14e4_44408ea348d64b71859757e3a0d06ba1.pdf
    • https://static.usrfiles.com/ugd/e481ce_7fb8c6d2fd8b4516a274237f01aefe08.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b865.bin
fc8610553a50fe03bdec9a758fc6bf45ebd172545670768ad99f05f8e48436c3
pdf-font-stream PDF embedded font (sfnt) at offset 0xB865 5696 bytes
font_01_sfnt_off0000cbe2.bin
bee97eadb464831d65478faa221fc130b0d9dd4a37adeaec76fcac17a05251b2
pdf-font-stream PDF embedded font (sfnt) at offset 0xCBE2 15936 bytes
font_02_sfnt_off0000fcb9.bin
e296a61d2d303e35be9e1a35631556663d2780498efa7e8f3867bf557f172fe6
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCB9 16164 bytes