Malicious PDF — malware analysis report

Static analysis result for SHA-256 432dc5b694ef9b3e…

MALICIOUS

PDF

97.7 KB Created: 2020-10-25 21:11:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-05
MD5: ada50bcafa2282ecc1530d326167b827 SHA-1: 42c28fa77591b0fd7eae2150537bc3fb0992794c SHA-256: 432dc5b694ef9b3e4a9a4cc6173b049a68b8a2ab6be98e2adf94033044eee185
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file contains a large number of links pointing to external PDFs hosted on disposable domains, indicating a link farm for SEO manipulation or to distribute malicious content. One critical heuristic identified a link to known malicious redirector infrastructure, suggesting a potential pathway to malware delivery. No scripts were extracted, but the overall structure and heuristics strongly suggest a malicious intent to lure users to external, potentially harmful, resources.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/aws?keyword=in+search+of+lost+time+pdf+proust In PDF document text
    • https://xofilovinavi.weebly.com/uploads/1/3/1/3/131379248/sotiketalomurat.pdfIn PDF document text
    • https://reredutubonuki.weebly.com/uploads/1/3/0/7/130775370/datukikew_fokagopa_jebiduvawov.pdfIn PDF document text
    • https://firerokuk.weebly.com/uploads/1/3/1/1/131164187/d2959817b214.pdfIn PDF document text
    • https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dekegu.pdfIn PDF document text
    • https://wekubuzebebam.weebly.com/uploads/1/3/0/7/130739705/c53b361c.pdfIn PDF document text
    • https://nagifinapu.weebly.com/uploads/1/3/2/6/132696111/7031810.pdfIn PDF document text
    • https://rafesotel.weebly.com/uploads/1/3/4/3/134321319/5651322.pdfIn PDF document text
    • https://mogijoduvide.weebly.com/uploads/1/3/0/8/130814471/2258d9a316.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/d956abae-6119-431a-b060-0ef1b30586ab/gonixejilarofejoxor.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ac62efba-0d11-4ec0-89cd-b1e182ec3e01/sazosedatejipiwumijadumip.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1b8938cc-2f67-45f5-8073-e7b30b69ff01/bipazute.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ed194722-f0b2-493f-8392-e5d40f8f60ae/sawoxukiliporugeg.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d2fd976c-a063-41d2-8db0-9c098f560b92/zelefuluba.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0495/4646/1336/files/xd_memory_card_best_buy.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0438/1281/5010/files/vorebaru.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0493/4811/6639/files/ruledepove.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/3071/5288/files/97966118860.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0501/0020/7777/files/27592147944.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b194cb5a-f422-42cb-9a12-9399571f25fc/nomusigulovuxug.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/53994d55-c0bf-45d9-8491-c8042f234713/91624143188.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8fdde51f-dad9-40b7-8af9-a475f2f301ae/nezaxanulabafizugomaf.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e673407f-eff2-40e3-87a6-491a8fb2f65d/vugonokusagalad.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a1d3ba2c-b159-400e-87e1-eec88043b068/61280447469.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000140dd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x140DD 5332 bytes
SHA-256: c1416e667481e470e77ba9b944b514ff9a7a45e25cc1f278e82b63bfb3dee61e
font_01_sfnt_off000152c4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x152C4 11736 bytes
SHA-256: 3fb36bd80d93fb14908e01396af310caf2af5089afefd17dd9c00256550d1516