Malicious PDF — malware analysis report

Static analysis result for SHA-256 421771c62ea40353…

MALICIOUS

PDF

78.8 KB Created: 2020-07-17 04:59:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e435ff307b0ebe05bc3fa5b7f659e893 SHA-1: 309f9f758e8653898c1630f33c944c206222c6f5 SHA-256: 421771c62ea403539d59cd2532a1780b2a154cc12fb1a65e6bca84205da1d57b
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous links to external websites, with a critical heuristic firing indicating a link to known malicious redirector infrastructure. The document body, though heavily obfuscated, suggests a lure related to 'binary tree data structure pdf' to entice clicks. The ML classifier strongly flagged this PDF as malicious, supporting the conclusion that it is designed to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=binary%20tree%20data%20structure%20pdf
    • http://files.sterlingequipment.us/uploads/1/3/1/4/131437064/2628530.pdf
    • http://files.service-netflix.com/uploads/1/3/1/4/131453068/51436c517b40762.pdf
    • http://files.cresapsociety.com/uploads/1/3/2/7/132740692/5867137.pdf
    • https://lizogugodube.files.wordpress.co
    • https://dasaxuxigu.files.wordpress.com/2020/07/fumurekavibube.pdf
    • https://sapojit.files.wordpress.com/2020/07/naluzopavisibatij.pdf
    • https://fumeperotozu.files.wordpress.com/2020/07/43867199830.pdf
    • https://lizogugodube.files.wordpress.com/2020/07/88591853624.pdf
    • https://kejaram.files.wordpress.com/2020/06/zusewixogariwe.pdf
    • https://mewazaxudo.files.wordpress.com/2020/07/10997586228.pdf
    • https://pijadajetami.files.wordpress.com/2020/06/vupisekobozujixeworavi.pdf
    • https://zovotapalu.files.wordpress.com/2020/07/96428909445.pdf
    • https://xilawirusit.files.wordpress.com/2020/06/52388612643.pdf
    • https://cdn.shopify.com/s/files/1/0434/0878/5562/files/24289684696.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/tanedikefiresemur.pdf
    • https://cdn.shopify.com/s/files/1/0429/3325/6345/files/mozazazufuxugejidinub.pdf
    • https://cdn.shopify.com/s/files/1/0432/0601/7186/files/pumabesotot.pdf
    • https://cdn.shopify.com/s/files/1/0431/6112/5013/files/21308820021.pdf
    • https://cdn.shopify.com/s/files/1/0429/9377/8837/files/89141775972.pdf
    • https://cdn.shopify.com/s/files/1/0431/8360/3876/files/jojeruvagoxexifurudode.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/94766401197.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e547.bin
ce377fdf7c7344ce2e43895ea19ef76f2e68a3c3f0ec7449f688f89c99dc3638
pdf-font-stream PDF embedded font (sfnt) at offset 0xE547 5040 bytes
font_01_sfnt_off0000f675.bin
eeb906e5405bf052d56f234407ad2ded852e8f903a82603e36b7df475cd1d5a7
pdf-font-stream PDF embedded font (sfnt) at offset 0xF675 17888 bytes