Malicious PDF — malware analysis report

Static analysis result for SHA-256 4d4cd563b1db493d…

MALICIOUS

PDF

53.6 KB Created: 2020-10-26 01:23:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 196a314ce8ed49ebae99f3f19df44a17 SHA-1: 500c1bf4c86b5523279a022a7cf8e12571292f46 SHA-256: 4d4cd563b1db493d440b226ed89f4815641cdbdffaea1ee77ab894ef4c6ee708
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with one heuristic specifically identifying a link to a known malicious redirector. The document body, though heavily obfuscated, contains text related to a transistor datasheet and a URL that matches the redirector. The presence of a large number of external PDF links suggests a link farm or SEO poisoning attempt, likely to obscure the malicious intent. No scripts were extracted, but the PDF structure itself facilitates the redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/aws?keyword=transistor+2n2222+datasheet+pdf
    • https://suzokixuvajix.weebly.com/uploads/1/3/0/7/130776208/8614398.pdf
    • https://lupolaluxu.weebly.com/uploads/1/3/2/6/132681144/533ae5baa0f3c.pdf
    • https://dajifavetesa.weebly.com/uploads/1/3/4/2/134234726/xonaja-jasin-gusoteviz-rubenatifitukom.pdf
    • https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/2697285.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.opentle.org
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0482/9937/6802/files/les_gommes_alain_robbe_grillet.pdf
    • https://cdn.shopify.com/s/files/1/0502/1155/3473/files/semiologia_porto_livro.pdf
    • https://cdn.shopify.com/s/files/1/0478/0952/7967/files/business_intelligence_development_studio_bids_2008_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/7777/1164/files/kedagabanaxirojijebuxiki.pdf
    • https://cdn.shopify.com/s/files/1/0483/6727/2087/files/kufap.pdf
    • https://uploads.strikinglycdn.com/files/95b0a42e-8bb5-4aff-8fe9-eaf3ce56b146/8490761106.pdf
    • https://uploads.strikinglycdn.com/files/ee135bc3-23ab-422a-b6b8-eb77f86c0a9b/kan_ik_op_een_50cc_scooter_rijden_zo.pdf
    • https://uploads.strikinglycdn.com/files/0a934f91-4dd4-4480-9d8d-78ee00047dab/gta_5_ceo_vehicle_cargo_guide.pdf
    • https://uploads.strikinglycdn.com/files/6e8cee1b-fc2d-4540-b612-439c6436595b/68459783985.pdf
    • https://uploads.strikinglycdn.com/files/4ca0f438-01fa-4ef3-b81d-f1845c8caab2/jigalamezikonivimaku.pdf
    • https://uploads.strikinglycdn.com/files/f0bee05b-73ec-46bf-9f0a-f944bbbda10c/kawuwesubadukezudiz.pdf
    • https://uploads.strikinglycdn.com/files/33fbc702-995b-420a-ba07-cb4c13f49ec6/41751945804.pdf
    • https://uploads.strikinglycdn.com/files/59158419-468e-42b6-a494-4631971b87e9/processes_systems_and_information_an_introduction_to_mis_ebook.pdf
    • https://uploads.strikinglycdn.com/files/e060ebe1-782e-47f1-8ddf-6ba89921e659/mimeviku.pdf
    • https://uploads.strikinglycdn.com/files/d824e720-da02-4be7-8d68-cf312a742e04/happier_tal_ben_shahar_free_down.pdf
    • https://uploads.strikinglycdn.com/files/0dffe79f-4be6-4661-a3d5-cd409f97b1d6/77302004811.pdf
    • https://uploads.strikinglycdn.com/files/536ade86-38ac-4f86-8caf-a6b770700d21/35826284396.pdf
    • https://uploads.strikinglycdn.com/files/c9802f91-2e38-4878-b7c1-be1703772aa9/missed_abortion.pdf
    • https://uploads.strikinglycdn.com/files/f2054884-83e2-44b0-9444-92ccf64f37b7/66343353636.pdf
    • https://uploads.strikinglycdn.com/files/aed10ab6-1b88-4e86-a7eb-c4cf1b3a8e1f/83032856591.pdf
    • https://uploads.strikinglycdn.com/files/0e7f32ed-9371-4c89-b05f-cbbd2228480e/memorial_service_invitation_template.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000728d.bin
02438777f66551c5cac4a50adb2ecd8b51067272ceb68afab85fd49345945770
pdf-font-stream PDF embedded font (sfnt) at offset 0x728D 4968 bytes
font_01_sfnt_off00008351.bin
d8e4b7f44dfb66ea49c7f1cefd345a391fade3fb548cc17de4cdbf151663dabd
pdf-font-stream PDF embedded font (sfnt) at offset 0x8351 6068 bytes
font_02_sfnt_off00009302.bin
9007a92b00996c68ee4bd750f836d121789c3f3a8bdab628d930f6e3c269f7f0
pdf-font-stream PDF embedded font (sfnt) at offset 0x9302 11796 bytes
font_03_sfnt_off0000ba02.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0xBA02 4324 bytes