Malicious PDF — malware analysis report

Static analysis result for SHA-256 3640bdf8161e0e70…

MALICIOUS

PDF

35.1 KB Created: 2020-11-07 10:39:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7b1ebe37daa9ac5a1f4ac8168a6f320b SHA-1: d0ef6b3d38c8e776442b51ead795a9c411892bc3 SHA-256: 3640bdf8161e0e70e3d855d875bf4f1af35443656a76e762be5ac1ee5b44614d
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded URLs, with heuristics indicating it is a malicious redirector and part of a link farm. The primary malicious URL identified is https://traffmen.ru/123?keyword=ge+profile+warming+drawer, which likely serves as a gateway to further malicious content or malware. The document body itself is heavily obfuscated and contains many of the extracted URLs, suggesting an attempt to disguise its malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffmen.ru/123?keyword=ge+profile+warming+drawer
    • https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/tevow.pdf
    • https://lujadogube.weebly.com/uploads/1/3/4/5/134522393/lunegozujitereper.pdf
    • https://galojegada.weebly.com/uploads/1/3/4/3/134364802/silujininilawez.pdf
    • https://gazetitorujij.weebly.com/uploads/1/3/4/5/134599815/nefalekalo.pdf
    • https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/fubumimig.pdf
    • https://nevikafujar.weebly.com/uploads/1/3/4/3/134380077/5514736.pdf
    • https://tivurenufetoza.weebly.com/uploads/1/3/4/2/134235987/daxokesiwiw_simutatig_dewumofurebamob_purizajefuzugan.pdf
    • https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/3373854.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/9579a7c0-0a46-4fa6-ac51-a2e009e80ee2/samsung_un32j5003_32_inch_1080p_led_tv.pdf
    • https://mekiperefef.files.wordpress.com/2020/11/lightroom_6.14_download_windows.pdf
    • https://wufigodek857813518.files.wordpress.com/2020/11/bosch_professional_glm_30_manual.pdf
    • https://fujebirejuku.files.wordpress.com/2020/11/lelebuvubu.pdf
    • https://wobonil.files.wordpress.com/2020/11/58436444283.pdf
    • https://uploads.strikinglycdn.com/files/6a736787-7a49-4c0f-ba15-7409bc275352/gulifuduweneribasejasumuk.pdf
    • https://uploads.strikinglycdn.com/files/adb053ba-98d6-4f2a-a38c-07471c273c2c/noleroporujexuginijategi.pdf
    • https://uploads.strikinglycdn.com/files/ff617c5e-3d48-46de-8f28-96c76892d5be/65735557705.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000459d.bin
ef4936fe470c4a3683c84624a526e0ff898101829c3c73b8d60e76184599f25e
pdf-font-stream PDF embedded font (sfnt) at offset 0x459D 5304 bytes
font_01_sfnt_off000057a8.bin
e5658542edc9df4d9369dd79ce925435ad52792226d1e20366a79359f135ffe4
pdf-font-stream PDF embedded font (sfnt) at offset 0x57A8 11940 bytes