Malicious PDF — malware analysis report

Static analysis result for SHA-256 5fe1013c6464b4ce…

MALICIOUS

PDF

47.8 KB Created: 2020-10-18 02:42:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1e44512535e663316b1f40529cfdd430 SHA-1: 496a2d9fb6ce9ea028e4a3226fb5724f1e6eebb7 SHA-256: 5fe1013c6464b4ceedae030dfe700522a672d25e9515ce21887de2b944a7c748
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a malicious redirector link disguised as a download for a photo translator application. It also hosts a large number of external PDF links, many of which point to benign content, suggesting a link farm or SEO manipulation tactic. The ML classifier strongly indicated maliciousness, and the presence of a known malicious redirector URL confirms this.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/123?keyword=triplens+photo+translator+apk
    • https://tarirubawapub.weebly.com/uploads/1/3/1/6/131606173/wakorexipo.pdf
    • https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/1d44b872.pdf
    • https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/wulupopopal.pdf
    • https://lowizozexide.weebly.com/uploads/1/3/0/7/130776176/9441920.pdf
    • https://cdn-cms.f-static.net/uploads/4374185/normal_5f8b7120ca825.pdf
    • https://cdn-cms.f-static.net/uploads/4368768/normal_5f8a8b2086d5a.pdf
    • https://cdn-cms.f-static.net/uploads/4365619/normal_5f8b6f41d8926.pdf
    • https://cdn-cms.f-static.net/uploads/4366029/normal_5f89277059979.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/e5d7ad1c-dc6a-4404-afda-438280b2812d/52671903823.pdf
    • https://uploads.strikinglycdn.com/files/1eb9859e-fef2-4a70-ae28-1096af163b21/gawexeruxexojepuja.pdf
    • https://uploads.strikinglycdn.com/files/cae627ba-67ee-44ac-aed5-922237a614fc/21028247562.pdf
    • https://uploads.strikinglycdn.com/files/cc2986df-438c-4556-9c20-ab2181584a46/wewevud.pdf
    • https://uploads.strikinglycdn.com/files/d7d5e789-ee0b-463f-8463-e5dab8f31947/imagenes_sensoriales_do_lazarillo_de.pdf
    • https://uploads.strikinglycdn.com/files/ad504ad4-f132-4747-beb6-fcbb14d94c80/23228395895.pdf
    • https://uploads.strikinglycdn.com/files/a78adb05-f33a-484c-b7ca-e8c4302732cb/91162055232.pdf
    • https://uploads.strikinglycdn.com/files/3dea7ab2-3cbc-405a-88ab-b4250fc32727/53532187420.pdf
    • https://uploads.strikinglycdn.com/files/5e0f09a4-0917-4121-b7b7-9ac6eae963b5/27823460783.pdf
    • https://uploads.strikinglycdn.com/files/62e7801e-4464-4edd-9719-e5361d6fdf08/lonigedanenifowadepobog.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000064ac.bin
8a2bbabca2546842d8cd86954aef0237d15f01dcfb70d3e3e4ee0281d17e21d4
pdf-font-stream PDF embedded font (sfnt) at offset 0x64AC 4920 bytes
font_01_sfnt_off00007551.bin
ad88f6be375ab3b5a1279987a1bdfac7447fda7f94adbf68e007fb5065a9a4b8
pdf-font-stream PDF embedded font (sfnt) at offset 0x7551 11332 bytes
font_02_sfnt_off00009b30.bin
aa844ae8691b184b22e8641a13f5e4f7be77e035d8e1189434bbea6a0555f82d
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B30 16488 bytes