Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c40497c1dd9943e…

MALICIOUS

PDF

51.0 KB Created: 2020-09-16 23:38:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 024c5f81b490b5056304246054e33931 SHA-1: 3f88e07ab51da291f60a61cfe86696da5d9e0ae5 SHA-256: 5c40497c1dd9943e0feccfd77ebf080f153fddc0b739c6197a545406f0a97c96
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, with one specifically identified as a malicious redirector pointing to 'https://ttraff.ru/wix?keyword=lexmark+ms310dn+service+manual'. The document body, though heavily obfuscated, contains text suggesting it is a service manual, a common lure for phishing or malware delivery. The presence of numerous other PDF links, many benign, suggests a link farm or SEO poisoning tactic to obscure the malicious destination. No scripts were extracted, but the overall structure and malicious URL indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=lexmark+ms310dn+service+manual
    • http://silefe.jihyunhong.com/uploads/1/3/0/8/130814687/zizeginomuxavegi.pdf
    • http://files.twtlministries.com/uploads/1/3/1/4/131406841/redupiserejuxix_fiwufom.pdf
    • http://files.jenlarussa.com/uploads/1/3/0/7/130739462/zofezagelefitek.pdf
    • http://xekenur.daxandivyboutique.com/uploads/1/3/0/7/130739101/6495983.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0431/5519/4011/files/73545262984.pdf
    • https://cdn.shopify.com/s/files/1/0437/3938/1912/files/38550407692.pdf
    • https://cdn.shopify.com/s/files/1/0437/9253/1617/files/clothes_worksheets_for_grade_4.pdf
    • https://cdn.shopify.com/s/files/1/0434/7042/2180/files/59830789178.pdf
    • https://cdn.shopify.com/s/files/1/0429/9338/5633/files/36559701169.pdf
    • https://cdn.shopify.com/s/files/1/0432/7053/7374/files/financial_reporting_council_act_2011.pdf
    • https://cdn.shopify.com/s/files/1/0432/8508/6364/files/modajowugivasozuzu.pdf
    • https://cdn.shopify.com/s/files/1/0480/9880/3875/files/fission_fusion_worksheet_nuclear_weapons_answers_key.pdf
    • https://cdn.shopify.com/s/files/1/0431/5004/9446/files/agronomie_cours.pdf
    • https://93775e36-0cf7-44dd-920e-9cca739a7e36.filesusr.com/ugd/80bfa9_c16fea47c97b4d2199e9427258e82c0c.pdf?index=true
    • https://b946b040-3972-449d-8156-e21c3750dfea.filesusr.com/ugd/784815_fd804d5fc79c48f985211c0901bf5dfb.pdf?index=true
    • https://a3f79fba-6e83-4fd6-b489-ebaaad02e059.filesusr.com/ugd/7d1dc9_a587162ae3624ce9bccac56905cfbd85.pdf?index=true
    • https://0f70fff6-d2e6-46c1-bcd4-e0afa4e4482e.filesusr.com/ugd/7a359d_92010369cf224cb9ac7c51a11879a239.pdf?index=true
    • https://1d601df0-0f97-4293-9f1c-e65b0ebb6512.filesusr.com/ugd/5926b4_97f8f42c4801442d806754591b30a218.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000086c4.bin
bfe14969c987318e2807024f8a3ce86cdcdd4496600987ff51a3dba2bc8e86f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x86C4 5576 bytes
font_01_sfnt_off000099b6.bin
3d16d52c7036dfe58783b040b290a2988e59bc86b42361fe3d8f2bc672ec5b0d
pdf-font-stream PDF embedded font (sfnt) at offset 0x99B6 10808 bytes