Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ea41732325e9fbb…

MALICIOUS

PDF

41.6 KB Created: 2020-08-08 03:47:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 324115a4b40c4284b1cf022d5f98fd65 SHA-1: e018ee41500eb4f11ca1c031c740b92970ef2e9f SHA-256: 5ea41732325e9fbb5deba2352de0c692f4e87680a53868fbb005e5cf783a61a6
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to a redirector service known to host malicious content. The ML classifier also strongly indicated maliciousness. The primary attack vector appears to be luring users to malicious sites via embedded links, likely as part of a phishing or scam campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=transformer+bushing+parts+pdf
    • http://files.marciasesthetics.com/uploads/1/3/1/6/131607010/mepavovaboluruw.pdf
    • http://files.cosmicrockbooklets.com/uploads/1/3/2/7/132740533/216a64a91bc.pdf
    • http://files.madlyeclectic.com/uploads/1/3/1/4/131483253/nuwitoduku_xafozovininu_lekilirox_navagad.pdf
    • http://nilelabof.vedajess.com/uploads/1/3/0/7/130738732/virifaravu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0431/0512/4516/files/24141924975.pdf
    • https://cdn.shopify.com/s/files/1/0436/7620/5209/files/wafanufidokusozovuwimi.pdf
    • https://cdn.shopify.com/s/files/1/0432/9209/8726/files/story_map_beginning_middle_end.pdf
    • https://cdn.shopify.com/s/files/1/0429/7824/6815/files/zafajilatifelu.pdf
    • https://cdn.shopify.com/s/files/1/0434/8212/0358/files/5785525340.pdf
    • https://cdn.shopify.com/s/files/1/0432/7990/9030/files/gmat_sample_test.pdf
    • https://cdn.shopify.com/s/files/1/0431/1518/4277/files/nakaliwotisem.pdf
    • https://cdn.shopify.com/s/files/1/0433/7329/7822/files/2540067083.pdf
    • https://cdn.shopify.com/s/files/1/0432/7315/8821/files/5492577532.pdf
    • https://cdn.shopify.com/s/files/1/0437/5651/9576/files/77580286718.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006532.bin
8e6d1a7097af3f8ec8fff0f553fb0670af4274117d9c152222dd09717509e9d3
pdf-font-stream PDF embedded font (sfnt) at offset 0x6532 5512 bytes
font_01_sfnt_off000077bb.bin
61e03248d15da0fa9138e0589f5611dbfac14c9c944337e4a11d355036d09beb
pdf-font-stream PDF embedded font (sfnt) at offset 0x77BB 10020 bytes