Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b269cdd309d61d7…

MALICIOUS

PDF

44.4 KB Created: 2020-08-26 05:57:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 288c0cc1b00ba865baaf0b2f8c6f72fa SHA-1: da1745ced8413701ba37d384a1250e903cd328e3 SHA-256: 5b269cdd309d61d7354e24e2d8f27b1c3a25fceec9e61e041a9faa6cddad4a18
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to a redirector service. The primary heuristic indicates that the PDF links to known malicious redirector infrastructure. While no scripts were extracted, the presence of numerous links suggests an attempt to direct users to potentially malicious content, likely as part of a phishing or scam campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=magisterium+la+torre+dorada+pdf+espa%25C3%25B1ol
    • http://gamexe.kelleyreneephoto.com/uploads/1/3/0/9/130969742/pimumunudijiruwu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0438/4423/9510/files/almost_blue_elvis_costello.pdf
    • https://cdn.shopify.com/s/files/1/0434/0154/3831/files/gamitosogevufijoza.pdf
    • https://cdn.shopify.com/s/files/1/0459/2366/4039/files/bootstrap_table_with_pagination_free.pdf
    • https://cdn.shopify.com/s/files/1/0430/9850/5369/files/sonulabef.pdf
    • https://cdn.shopify.com/s/files/1/0431/1698/6534/files/71756818632.pdf
    • https://cdn.shopify.com/s/files/1/0431/7511/6960/files/introduction_to_analysis_rosenlicht.pdf
    • https://cdn.shopify.com/s/files/1/0433/8394/7414/files/fowewoxibugu.pdf
    • https://cdn.shopify.com/s/files/1/0431/9058/3458/files/moligizililipozal.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005f3c.bin
b8e7f7fad8aeace577f7b005f4f7791a909779b2fb058b06ade34f60c8abfcd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F3C 5356 bytes
font_01_sfnt_off00007156.bin
1468b3bc45b44a63c295f663c0364233cec74f163d5b184d048698bb39472a68
pdf-font-stream PDF embedded font (sfnt) at offset 0x7156 10904 bytes
font_02_sfnt_off000094b0.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x94B0 4324 bytes