Malicious PDF — malware analysis report

Static analysis result for SHA-256 40e91e6f100be443…

MALICIOUS

PDF

41.3 KB Created: 2020-10-11 12:37:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-26
MD5: c4e8ab0fc248f6c99ac3580b3b34e262 SHA-1: f5cbe4e6e0f1d0820ea1564d8aa4e730d52d89b7 SHA-256: 40e91e6f100be4436591693f6e323ee883262c9beccb8924c53bb23cfab7bd43
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a lure for "Plants vs zombies heroes gem hack" and embeds multiple links, including a critical redirector link to cctraff.ru. The document body itself is heavily obfuscated but contains references to the lure and the malicious URL. The presence of numerous external PDF links suggests a link farm or SEO poisoning tactic to distribute the malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=plants+vs+zombies+heroes+gem+hack In PDF document text
    • http://files.adventuresav.com/uploads/1/3/1/4/131408970/241a9da.pdfIn PDF document text
    • http://files.carnoules-au-coeur.com/uploads/1/3/0/8/130814516/5893769.pdfIn PDF document text
    • http://sevaju.rozalindjester.com/uploads/1/3/1/4/131408024/1832214.pdfIn PDF document text
    • http://dozoxi.fusionsoapquilt.com/uploads/1/3/0/7/130739173/rujexiwemozafe-sapexin.pdfIn PDF document text
    • http://files.louiselindley.com/uploads/1/3/1/6/131636736/1221426.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0484/9500/1750/files/somekogejelamerax.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0503/3964/3542/files/molar_ratios_worksheet_practice_problems.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/8814/9654/files/85053537883.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0427/9464/7719/files/24046075880.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/2010/7424/files/mufadefodijararo.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0437/1762/3957/files/rawages.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0438/2290/7554/files/80162917298.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0486/1706/2558/files/native_american_stick_people.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/3183/8368/files/fudejolino.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0481/7377/7045/files/latitude_e6420_broadcom_ush_windows_10.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0436/9950/3254/files/dc_legends_hack.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063db.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x63DB 5528 bytes
SHA-256: f6bcb8845161b98232a4a5cbdf960238e8d32f16d487a85ee74205ef0e121c32
font_01_sfnt_off00007689.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7689 9984 bytes
SHA-256: 6e659a1d435229eb06641ad92be39d4e750d4fc8a4c067726c2a5a5ed53a156b