Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f1035a1531fd16c…

MALICIOUS

PDF

54.5 KB Created: 2020-10-23 13:17:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-16
MD5: 8b4a3e3b661ac87abbae1623e057c06f SHA-1: 9e29bf29453f7a7bd4d686201f6be2ace92bc38a SHA-256: 2f1035a1531fd16c8fe68bd279fda23c7d61c921a0c5f279a9220d0477832bc2
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a heuristic firing for a malicious redirector link pointing to 'https://cctraff.ru/pify?keyword=jeu+moto+cross+apk', which is presented in the document body as a game download lure. The sample also exhibits characteristics of a PDF link farm, with numerous embedded URLs, some of which are hosted on S3 buckets. While no scripts were explicitly extracted, the presence of embedded URLs and the redirector link strongly suggest an attempt to lead the user to malicious content, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/pify?keyword=jeu+moto+cross+apk In PDF document text
    • https://cdn-cms.f-static.net/uploads/4373992/normal_5f8a8d0d0c388.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366017/normal_5f89fdf2f1d7d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4384655/normal_5f8e4b04bba95.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365627/normal_5f892d8a7b70d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367004/normal_5f87623c17b03.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365662/normal_5f874e1cf404d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367007/normal_5f894be93249f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374535/normal_5f8af118f2c73.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/babuxufarizuxur/vefeligis.pdfIn PDF document text
    • https://s3.amazonaws.com/tesotiwapax/wavovelo.pdfIn PDF document text
    • https://s3.amazonaws.com/mijedusovineti/bufakag.pdfIn PDF document text
    • https://s3.amazonaws.com/vavale/applied_economics_for_a_progressive_philippines.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0503/7696/6342/files/54764281601.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0431/7652/5984/files/utorrent_stuck_on_connecting_to_peers_reddit.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4d1f8c74-d25e-4f98-a76a-cda9dc26bbee/nofebizunixege.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/28cc7085-4ea2-4ca6-a0a9-ac8d4056de83/79501170005.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ef1195b4-9ec3-4f0e-a1f6-fbc89374f7a1/45013965844.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0496/5213/8137/files/chronicles_of_narnia_with_pictures.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0499/3210/7937/files/70924252278.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0438/4263/3890/files/piliwemepuvirokezi.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0483/1117/3275/files/vibunod.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0483/6153/7689/files/vakaseterovewobatizimasu.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off00009770.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9770 28684 bytes
SHA-256: f2623dbd7a1d34ce2f2855360f6bed1fd56642e51824700a509ed353404ef64e
font_00_sfnt_off0000647d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x647D 5100 bytes
SHA-256: 8368582c92e52fd5bf976c7d690aede7404d5df93967ab3ffa28e7dad56f0c80
font_01_sfnt_off000075c8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x75C8 10016 bytes
SHA-256: 101b2b3ef8a25e495bb59926827064f0c322b7c05474af6557a7bcff85ce44f0