Malicious PDF — malware analysis report

Static analysis result for SHA-256 44df4ef6797ed4f8…

MALICIOUS

PDF

34.9 KB Created: 2020-10-25 21:07:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: 46b214bcbe931986601754a2453dcc05 SHA-1: 34ab4da9cb3d0054fc51be5eec29a2b31be5bfc5 SHA-256: 44df4ef6797ed4f828da215f575b33b74037684318f553e05797937133a9e5c1
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous links to external PDFs, many of which are hosted on redirector domains. The document body, though partially corrupted, includes a URL that points to a known malicious redirector, suggesting an attempt to lead the user to malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9982

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/123?keyword=ringcentral+phone+app+user+guide In PDF document text
    • https://cdn-cms.f-static.net/uploads/4367960/normal_5f8c9dd57bd03.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4381536/normal_5f8e27ee5a999.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375705/normal_5f91cac080272.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366309/normal_5f8a42e315fd3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4388271/normal_5f8e0c4796aef.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4380228/normal_5f8c9125c878f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369505/normal_5f8a61dd00d02.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366306/normal_5f874b7f92a9d.pdfIn PDF document text
    • https://sanuvexugivi.weebly.com/uploads/1/3/1/6/131606490/2488786.pdfIn PDF document text
    • https://firedisivimi.weebly.com/uploads/1/3/0/9/130969818/3c38ac2f50fe.pdfIn PDF document text
    • https://xonuvalax.weebly.com/uploads/1/3/1/4/131437330/wifaw-kixubedukawab.pdfIn PDF document text
    • https://farupixin.weebly.com/uploads/1/3/4/3/134314126/746342.pdfIn PDF document text
    • https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/tolafet_dipaxenovu_bopirix.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379839/normal_5f929f8fe51d5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4372723/normal_5f8d517670c2e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391642/normal_5f94ca7884b0e.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/6cf2981f-7a98-43ce-9a1d-92a3a7f86130/27984313671.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4ef01a43-ae17-47ed-9f0c-f1dffb9d900f/kugetokufobenebosi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/36187733-be7f-4c8d-a615-d0322dacd9f1/voniba.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8e90770a-f422-4051-b4cd-761580965a6f/fijugojep.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4b0c4caa-7d2f-4c91-a1d5-6c3936758353/bakagaxa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c9b1a9de-3a97-4149-9a5c-3553f42e9f5a/timewuzotapilo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/89e94260-99a2-4219-b4a1-66168a14c1c2/2465038714.pdfIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000051bf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x51BF 5340 bytes
SHA-256: f48fece2fc0217d2c1534b347a8d6f32dd609bbe34f13f7566dd44bd48a543ae
font_01_sfnt_off000063d7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x63D7 10340 bytes
SHA-256: 6404af0c866807b1b5d41302cf908edc35655f6957c8acb1d11a8667afe2861f