Malicious PDF — malware analysis report

Static analysis result for SHA-256 1288de383f6c5f0f…

MALICIOUS

PDF

47.3 KB Created: 2020-08-12 09:02:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 78a9ab065be84d1da8a4d310c8441e18 SHA-1: c851353c893d319900c8f8d72a8685da02a89a62 SHA-256: 1288de383f6c5f0f06cdc0cf10a344d2e76fe7b76cf93de38917bd44bc9f3d2b
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with one identified as a malicious redirector. The ML classifier also flagged the document with high confidence. The presence of many external links suggests an attempt to manipulate search engine results or lead users to malicious sites, potentially for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=tinkle+digest+stories+pdf
    • http://mekulomik.exploreyourjourney.com/uploads/1/3/2/6/132681670/jemajezipadug-kajexemazegigo-kibumip.pdf
    • http://files.chinapivotsource.com/uploads/1/3/0/7/130776728/3768861.pdf
    • http://xujeroka.kolotproject.net/uploads/1/3/1/3/131383943/zibidatebipojevuwe.pdf
    • http://files.cninc.org/uploads/1/3/2/7/132740479/5324237.pdf
    • http://regebig.makewonder.blog/uploads/1/3/1/0/131070487/8344664.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0431/1724/8672/files/fokodorok.pdf
    • https://cdn.shopify.com/s/files/1/0431/8180/1629/files/26026789237.pdf
    • https://cdn.shopify.com/s/files/1/0430/5354/7677/files/gesiku.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/87463685859.pdf
    • https://cdn.shopify.com/s/files/1/0440/7286/1848/files/polipiragaliwonubuziwapi.pdf
    • https://cdn.shopify.com/s/files/1/0431/4189/0210/files/pdf_split_to_jpg.pdf
    • https://cdn.shopify.com/s/files/1/0432/9350/7739/files/levonuvonore.pdf
    • https://cdn.shopify.com/s/files/1/0435/7016/7967/files/national_building_cost_manual.pdf
    • https://cdn.shopify.com/s/files/1/0436/1096/4131/files/wizetusajutuluxomitoxuro.pdf
    • https://cdn.shopify.com/s/files/1/0432/7342/0965/files/70717703868.pdf
    • https://cdn.shopify.com/s/files/1/0433/2093/4558/files/91619665312.pdf
    • https://cdn.shopify.com/s/files/1/0430/5806/9655/files/vobavu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f14.bin
92c5b52788c62b9f163c72cfb074624b30b9faaefe42203c572383ead58ecff9
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F14 4800 bytes
font_01_sfnt_off00007f6d.bin
59a5803dc8d5efae2c1e3025939c795047e79d159a60103e22d10c3a16485c13
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F6D 10244 bytes
font_02_sfnt_off0000a261.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0xA261 4324 bytes