Malicious PDF — malware analysis report

Static analysis result for SHA-256 1c2da4092e633b3b…

MALICIOUS

PDF

43.9 KB Created: 2020-10-19 02:02:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 9d1d5cc2ae59b27ee91784fb73e9641c SHA-1: 951ddec533ba96c9bcbed7f9e79c36247909710d SHA-256: 1c2da4092e633b3b0bd3661984a77904ccbaa2d4d42b8dc10dcd5bb5061a0b30
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to disposable hosting and redirect to known malicious infrastructure. The document body, though heavily obfuscated, contains a URL that appears to be part of a lure for a 'Georgia driver's permit manual'. This suggests the PDF is designed to redirect users to malicious sites, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/123?keyword=georgia+driver%2527s+permit+manual In PDF document text
    • https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/dolopitubolagu.pdfIn PDF document text
    • https://wefejakero.weebly.com/uploads/1/3/0/8/130814310/zuvoxikemewo_vakafezupezuxu_pawunu_dukezumokowifam.pdfIn PDF document text
    • https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7304884.pdfIn PDF document text
    • https://botubadixebom.weebly.com/uploads/1/3/1/4/131407995/zedopomibonuvimewop.pdfIn PDF document text
    • https://zuxubemusaf.weebly.com/uploads/1/3/1/4/131453996/7548099.pdfIn PDF document text
    • https://pagofere.weebly.com/uploads/1/3/1/3/131398194/diradub.pdfIn PDF document text
    • https://folukufisika.weebly.com/uploads/1/3/1/3/131384255/6b12bd62d596563.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/30e6b4a1-f5d1-4066-8691-808b03efcac1/95224972909.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ac0f21f1-a67d-4720-af1d-1cb4d2b4d19a/dapewulawubaz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/becd1d7f-f48c-496b-834b-2ae712bcccb9/32785148020.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7cb7be99-3dcf-4e19-b05c-92716a0156cb/53043973594.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4f5ce8fd-85da-4a95-b785-88d8a3d4be6f/24180876031.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6fb269f1-9897-47e2-ac90-e59948c19d1a/bizaxod.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0f34eb4e-9854-478b-a1b4-b941766b3540/robagizuki.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/73429430-d843-4d58-aae4-a27a8e6cdb15/51731715364.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f2f50a80-452f-4a88-a3ec-288fdae7ab14/bimujesodififabozax.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bb5bc4b0-7647-4554-ae53-e262018818e5/pifimerenuw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/148ec976-2b29-49ae-8a4b-d7079f5dac81/wavosumodunutijarufuzuv.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c9398158-1aa4-4b33-b36d-93722d8b8951/bovur.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa972e5f-7370-4a24-ac51-ebe7601069e8/gifiresasuvanoxunivof.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cfec0cba-7bfe-41e6-aace-8896050a5ff1/14799413625.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/367dd16a-8227-407a-a190-f6591b6387e8/wanupenabusobatudidedov.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006cec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6CEC 5404 bytes
SHA-256: f679f7f3516ee8ae10b4f335912ca87c35c15ddb2381f1cd7fb8c3b02f4ae203
font_01_sfnt_off00007f51.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7F51 10196 bytes
SHA-256: 8c3a51cc764ec1959089778614e6972f424985207c75dff2169888eb41b225e5