Malicious PDF — malware analysis report

Static analysis result for SHA-256 45255ef147d21764…

MALICIOUS

PDF

74.3 KB Created: 2020-12-21 10:49:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-17
MD5: dfc9ba6c5e7e607c55ed809043063e37 SHA-1: 7a6206c749a196f2652b88c522018f4d5f0dfd7f SHA-256: 45255ef147d21764f4604536dcad406368279a163a490f60bd23db303fd501dc
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous embedded links, with one specifically identified as a malicious redirector. The document body, though heavily obfuscated, contains text related to 'Magica travel agency match 3 puzzle games', suggesting a lure to disguise the malicious intent. The presence of a link farm and a malicious redirector indicates an attempt to drive traffic to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9399

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/strik?utm_term=magica+travel+agency+match+3+puzzle+games In PDF document text
    • https://pidofuvu.weebly.com/uploads/1/3/0/7/130739764/2860498.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/a639147f-2a10-4cd3-9fe4-6c6d39c1e9f8/44007985024.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2b100535-98fe-4684-a697-01202ca52f7b/89866175799.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b37b21f0-463f-4bae-acf0-abef6ffd86d6/bumupuxivixe.pdfIn PDF document text
    • https://s3.amazonaws.com/posufij/gonepotozuzago.pdfIn PDF document text
    • https://s3.amazonaws.com/roxawo/political_cartoons_activities_for_american_history_answers.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc55f48bdb33045eee0080d/t/5fc6593df3de5e49b53dfdb1/1606834493172/rechargeable_batteries_deals.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b3360c46-9d0b-4fd8-bdf4-487f508863f6/estado_de_puertos_litoral_directemar.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f8fafe12-8f6f-4762-91c4-c9893a8bd5d7/radazusojokuviz.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc58a1012facd59cecc81e0/t/5fd645a6481cfa31adc37565/1607878060345/66748391252.pdfIn PDF document text
    • https://s3.amazonaws.com/lukepepe/dnd_5e_scholar_pack.pdfIn PDF document text
    • https://s3.amazonaws.com/patotale/android_root_apps_no_pc.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/68c16476-b3d7-47cc-9d0e-cdb7f8985fb3/kileguforidolajodo.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fdcb81cb919dd0c3e451148/t/5fdd1412365f8f1a3b11751d/1608324116074/95489703685.pdfIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e7ee.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE7EE 6676 bytes
SHA-256: 657ecd41de71d6cc26ea63214dcfece046f6447d6d4f661ddd1c7c509279b1e4
font_01_sfnt_off0000f8c4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF8C4 5728 bytes
SHA-256: 21ebbbc17c24884e0e83488c8b18d08fdb019e66f6c1c3353272e64ff2d5f015