Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c235ec23fb41b97…

MALICIOUS

PDF

84.9 KB Created: 2020-08-09 04:56:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6f8d09a6158c3dc1ccbbe58df43685fa SHA-1: abbf81078f994e3a4bb1947ad6a6107be3c8b824 SHA-256: 5c235ec23fb41b9712752cdde02b43bfd1f6e6529a32ac0a23af0b37ffbe7404
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with one identified as a malicious redirector. The ML classifier strongly indicated maliciousness, and the document body, though heavily obfuscated, contains text related to the redirector's keyword. The presence of many external links suggests an attempt to distribute malicious content or engage in SEO manipulation for malicious purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=atherosclerosis+treatment+pdf
    • http://files.ashdownsafety.co.uk/uploads/1/3/1/3/131383743/9711047.pdf
    • http://files.scottontherocks.com/uploads/1/3/0/8/130873804/407497.pdf
    • http://files.burlingamefootball.net/uploads/1/3/2/7/132740743/lipisemiris.pdf
    • http://files.swiptt.com/uploads/1/3/2/7/132740337/rezugil.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0427/6482/8838/files/75735336105.pdf
    • https://cdn.shopify.com/s/files/1/0429/6966/1589/files/rodexubugi.pdf
    • https://cdn.shopify.com/s/files/1/0430/4896/0151/files/88126673034.pdf
    • https://cdn.shopify.com/s/files/1/0433/3705/6411/files/31783965769.pdf
    • https://cdn.shopify.com/s/files/1/0437/7162/5621/files/danisafamujadodigosapoxov.pdf
    • https://cdn.shopify.com/s/files/1/0437/8581/4177/files/24319429010.pdf
    • https://cdn.shopify.com/s/files/1/0431/1390/6333/files/ferew.pdf
    • https://cdn.shopify.com/s/files/1/0429/6661/4175/files/track_phone_number_free.pdf
    • https://cdn.shopify.com/s/files/1/0439/2907/5880/files/star_trek_the_motion_picture_watch_online.pdf
    • https://cdn.shopify.com/s/files/1/0431/7675/5349/files/92734667707.pdf
    • https://cdn.shopify.com/s/files/1/0428/5346/6271/files/56419322832.pdf
    • https://cdn.shopify.com/s/files/1/0428/5127/0823/files/wurolujigubironug.pdf
    • https://cdn.shopify.com/s/files/1/0433/9315/5230/files/momagunadiradux.pdf
    • https://cdn.shopify.com/s/files/1/0432/4923/8178/files/lubujuwi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001107a.bin
a46f38b2ba73e8282f35e7c0d7021f97afb262c65882df5e053228d5de7a8e06
pdf-font-stream PDF embedded font (sfnt) at offset 0x1107A 5384 bytes
font_01_sfnt_off000122a0.bin
648f0e3866242df69734df97b1d36ed297f319e1c2ef4aedcf892f8dfb3eac0c
pdf-font-stream PDF embedded font (sfnt) at offset 0x122A0 10456 bytes