Malicious PDF — malware analysis report

Static analysis result for SHA-256 11346d5f4ed6f3a8…

MALICIOUS

PDF

46.9 KB Created: 2020-08-22 12:16:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f8f85b2d1cd46a9fc65f6670ddea358f SHA-1: a864f599441f2a7d5b39987f71c4600bc8f838cf SHA-256: 11346d5f4ed6f3a8ff75d9a84b0df9989379ea86a136b2367987174f7dbd4b36
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to a redirector service known to host malicious content. The document body, though heavily obfuscated, contains a URL that leads to this redirector. This indicates a likely attempt to direct users to malicious sites, potentially for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=killington+snow+report+10+day
    • http://files.illuminolightingco.com/uploads/1/3/1/4/131406610/8927207.pdf
    • http://files.mikesfamoussteaksandsubs.com/uploads/1/3/0/7/130739227/316198f990.pdf
    • http://files.bluepeterboathire.com/uploads/1/3/1/4/131437363/a1b8fed3.pdf
    • http://files.monkeybackart.com/uploads/1/3/0/7/130775592/55e6091fb6beaf.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0431/5335/8999/files/kudosiw.pdf
    • https://cdn.shopify.com/s/files/1/0440/5533/0981/files/tukaretazimudapukizu.pdf
    • https://cdn.shopify.com/s/files/1/0428/3983/4780/files/quest_list_osrs.pdf
    • https://cdn.shopify.com/s/files/1/0447/9103/8118/files/apex_reading_test_3_answer_key.pdf
    • https://cdn.shopify.com/s/files/1/0438/4410/8445/files/11267400122.pdf
    • https://cdn.shopify.com/s/files/1/0431/9779/2420/files/jiliwesewewuz.pdf
    • https://cdn.shopify.com/s/files/1/0435/4165/9797/files/miss_celie_s_blues_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0435/9448/1823/files/nilinixikigedirizivozo.pdf
    • https://cdn.shopify.com/s/files/1/0428/5943/0054/files/12463157706.pdf
    • https://cdn.shopify.com/s/files/1/0438/2693/8018/files/72238848176.pdf
    • https://cdn.shopify.com/s/files/1/0447/4676/8535/files/statistical_methods_for_survival_data_analysis_3rd_edition.pdf
    • https://cdn.shopify.com/s/files/1/0431/4755/9067/files/clicker_heroes_import_cheat.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000641e.bin
5f0b84cb0aa76137efdce6129591dc634694b31af155b2c0e1342369421e3659
pdf-font-stream PDF embedded font (sfnt) at offset 0x641E 5272 bytes
font_01_sfnt_off00007634.bin
dc99970e98db7946501b90667b0aba03b6ea4c2523ff1b78cdf76ba3df4218e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x7634 13092 bytes
font_02_sfnt_off0000a082.bin
ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230
pdf-font-stream PDF embedded font (sfnt) at offset 0xA082 4324 bytes