Malicious PDF — malware analysis report

Static analysis result for SHA-256 178e0faa4132f956…

MALICIOUS

PDF

126.4 KB Created: 2020-08-12 18:48:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2a6e2d7a7296fa1ce8122eb2bc56b1f3 SHA-1: cdc22ccd2b4b54ae4ae927d0a94de37b81ace0ec SHA-256: 178e0faa4132f9563faba3d24bb88b9df975b16e5c652a3e369bcb8d8931b1b6
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm and a redirector to a known malicious URL, indicating an attempt to lead the user to malicious content. The document body, though heavily obfuscated, contains text related to a story book and a URL that matches the malicious redirector, suggesting an advance-fee scam lure. The presence of numerous embedded links, many pointing to Shopify, further supports the link farm heuristic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=ramayana+story+book+in+english+pdf
    • http://files.foundephemeraart.com/uploads/1/3/0/7/130739740/4038351.pdf
    • http://files.mountainandocean.org/uploads/1/3/1/3/131381055/wazebax_solotumobikoz_gelan_zujitimu.pdf
    • http://mesefera.hsfhomeconnections-hilton.com/uploads/1/3/1/6/131637309/nofawejomowunu.pdf
    • http://files.theahealer.com/uploads/1/3/2/6/132695543/6474107.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://www.opentle.org
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0437/3803/8423/files/zilivebawegiduroxi.pdf
    • https://cdn.shopify.com/s/files/1/0434/1334/0312/files/18461713373.pdf
    • https://cdn.shopify.com/s/files/1/0431/7285/5967/files/differential_equations_blanchard_4th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/50398535586.pdf
    • https://cdn.shopify.com/s/files/1/0437/5022/8119/files/what_is_bioterrorism.pdf
    • https://cdn.shopify.com/s/files/1/0429/2083/7279/files/benedictine_rule_of_life.pdf
    • https://cdn.shopify.com/s/files/1/0433/6559/7342/files/tratamiento_para_caries_dental.pdf
    • https://cdn.shopify.com/s/files/1/0433/4462/5822/files/brothers_karamazov_penguin.pdf
    • https://cdn.shopify.com/s/files/1/0432/7355/2028/files/mepixid.pdf
    • https://cdn.shopify.com/s/files/1/0435/2652/0986/files/77773221227.pdf
    • https://cdn.shopify.com/s/files/1/0432/5320/3104/files/11769553439.pdf
    • https://cdn.shopify.com/s/files/1/0436/2030/3006/files/75645408831.pdf
    • https://cdn.shopify.com/s/files/1/0434/5734/7749/files/93851660309.pdf
    • https://cdn.shopify.com/s/files/1/0433/6500/7509/files/xagetekokiwudesezakewaguw.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • http://www.gnu.org/licenses/lgpl.htmlRegularDanhHong
    • http://www.geocities.com/dnhhng
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00013df2.bin
da609cd90ce72eb01192bcbb53cdca29dacc99c29e6767041bde1f0915cf1668
pdf-font-stream PDF embedded font (sfnt) at offset 0x13DF2 5556 bytes
font_01_sfnt_off000150ac.bin
601ff2313c148c0d458a5f8f06674ea56627a0d971c5b0cdc135d0396c871027
pdf-font-stream PDF embedded font (sfnt) at offset 0x150AC 2404 bytes
font_02_sfnt_off00015af1.bin
eb903a4bcabb0673128613fc2c6a3b3be6b6be0204d11159aa2f590e1d82ee93
pdf-font-stream PDF embedded font (sfnt) at offset 0x15AF1 3740 bytes
font_03_sfnt_off00016662.bin
f3e5403e201cb4aabba4862e9d17066d78d8c70691ea1ba4a98ac01fb06a352c
pdf-font-stream PDF embedded font (sfnt) at offset 0x16662 4820 bytes
font_04_sfnt_off000174f8.bin
eb74435aa33c92ccb841bb7a3a6ac50bdb5358d8b69712c509354d74473a37e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x174F8 2340 bytes
font_05_sfnt_off00017fc1.bin
62a6722e0a7780ce92c38fa958df9f2a9949d21e8884ca563b6443ce5db754b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x17FC1 3912 bytes
font_06_sfnt_off00018f15.bin
6c396c11f6ae740f8937989293ce789070d853422a7f4c875ffa694795473d63
pdf-font-stream PDF embedded font (sfnt) at offset 0x18F15 6992 bytes
font_07_sfnt_off0001a231.bin
9f77b41d25b92864968d64aedadddc2d35d72c4b53ff871cbfd7171df04a48a2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A231 12744 bytes
font_08_sfnt_off0001c9b7.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C9B7 4324 bytes
font_09_sfnt_off0001d7be.bin
eed323ad3814475636656456199bc6789deed97d9cfd340b4d3d5e82db9b01bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D7BE 4548 bytes