Malicious PDF — malware analysis report

Static analysis result for SHA-256 14cc04e9d68e696d…

MALICIOUS

PDF

40.8 KB Created: 2020-09-17 00:09:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 590179b86ef8fb6f1bf366eb5cb9d7c9 SHA-1: 449ee6116d3ac6ad31e715ea20d80ae6a15e123d SHA-256: 14cc04e9d68e696dcd6e89d629d5b81f5bfe320ba88a9c58d952b0a36d3033e3
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, with one specifically identified as a malicious redirector. The document body, though heavily obfuscated, contains text related to a product search, suggesting a phishing lure. The presence of numerous external PDF links further indicates a link farm designed to distribute malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=pa5109u-1brs+replacement+battery
    • http://vuvage.raincoatrun.com/uploads/1/3/0/8/130874683/vazux.pdf
    • http://files.thefashionanalyst.com/uploads/1/3/1/3/131383624/wezunawe.pdf
    • http://gemirilun.tigerunstrong.com/uploads/1/3/2/6/132696128/wivetunix-famekubutevilox-polag.pdf
    • http://newakejag.noordzeebanket.com/uploads/1/3/2/8/132814930/tivurivede-kidefini-pozefiwununo-jolixujobiju.pdf
    • http://vitopan.casinopromos4u.com/uploads/1/3/1/1/131164250/a40076d261f628.pdf
    • http://fuvax.youngbabuu.com/uploads/1/3/1/3/131380767/60f2f95b35db.pdf
    • http://togise.soundteaching.ca/uploads/1/3/1/8/131871578/velibarar.pdf
    • http://xabilibik.cvpolygraph.com/uploads/1/3/1/4/131453574/forokulam.pdf
    • http://files.learninginafterschool.org/uploads/1/3/0/7/130739174/wikoluranevetulik.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://5d8a3448-d640-43de-a1a1-6f1f55c82159.filesusr.com/ugd/2f3ac6_06efdab3b53a4e61b4ba218b4222bade.pdf?index=true
    • https://b539289d-d958-4845-995d-a72f9282bd8a.filesusr.com/ugd/ab922d_79662b69bb024684bb6a029c24223daa.pdf?index=true
    • https://ae4d4977-eedb-4eb8-b103-b266c01db728.filesusr.com/ugd/5dc3ca_0e64f610058644f985482832a290e319.pdf?index=true
    • https://1463c31b-20f7-49ab-a9f3-ed074a0c4b8f.filesusr.com/ugd/5b9a87_1391a00ebaa74e44ac54be59ab3e320d.pdf?index=true
    • https://73a0b51a-efef-4f58-adc2-3bb4b5359cef.filesusr.com/ugd/225520_3291a54682c24f0c993180a5f5cc9e64.pdf?index=true
    • https://2ae33f5c-1409-46ff-a1cc-15501b574369.filesusr.com/ugd/3bca44_3da13165016744dc94f80b64f4afb1ac.pdf?index=true
    • https://6fb2f127-278a-4d1a-939a-c8b4cb754561.filesusr.com/ugd/cb4a18_5c4adf0fee2640ae8af5915bec545e69.pdf?index=true
    • https://74f429ed-533c-4f80-ba28-1f1ea472cf7c.filesusr.com/ugd/7c1f05_fba208cad1ec4cb9a21a9be7a230d7b4.pdf?index=true
    • https://c8521453-3955-4e8a-b154-a46b46e217db.filesusr.com/ugd/4c1554_70ec98fafd764c2c9c8dfcb652ed360c.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005fe1.bin
0a2a892e9245c8684eec53167d64cbed0fdfcf7e30b4605729a0e48cdf759c73
pdf-font-stream PDF embedded font (sfnt) at offset 0x5FE1 5828 bytes
font_01_sfnt_off000073b1.bin
9094f4aa0ada5abfab0852143b591a30106c59bae98a69b54416c227f1b864df
pdf-font-stream PDF embedded font (sfnt) at offset 0x73B1 10148 bytes