Malicious PDF — malware analysis report

Static analysis result for SHA-256 600b29e1ecd51983…

MALICIOUS

PDF

44.4 KB Created: 2020-08-13 05:54:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9e198f0ef3c9efef872f826492d7f71f SHA-1: c4e48fccbe1c2dac37df52ede0aec294817a6b97 SHA-256: 600b29e1ecd51983e09bb6b71121e3c5c3eaa5e33173884895520a62545424df
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm designed to attract users searching for software activation keys, directing them to a malicious redirector. The embedded document body text, though partially corrupted, contains keywords related to software activation and download, reinforcing the lure. The presence of numerous external PDF links suggests an attempt to manipulate search engine results for malicious purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=foxit%20phantompdf%20activation%20key%20free%20download
    • http://files.milescollegenationalalumni.com/uploads/1/3/1/4/131483184/1393220.pdf
    • http://files.tropicgardengems.com/uploads/1/3/2/6/132696029/3720.pdf
    • http://files.kyongburke.com/uploads/1/3/2/8/132815866/3556492.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0437/8719/0430/files/lugizuvisapizudixe.pdf
    • https://cdn.shopify.com/s/files/1/0439/5171/8558/files/18035454625.pdf
    • https://cdn.shopify.com/s/files/1/0432/1820/6887/files/bunaxokekosulilurev.pdf
    • https://cdn.shopify.com/s/files/1/0429/1959/2102/files/88406707839.pdf
    • https://cdn.shopify.com/s/files/1/0428/2351/6323/files/dudomapizuvolira.pdf
    • https://cdn.shopify.com/s/files/1/0438/9309/6600/files/kaginogagefoda.pdf
    • https://cdn.shopify.com/s/files/1/0430/9159/1317/files/5603234340.pdf
    • https://cdn.shopify.com/s/files/1/0431/4189/0210/files/samizekivedapageb.pdf
    • https://cdn.shopify.com/s/files/1/0430/0197/0837/files/57410734076.pdf
    • https://cdn.shopify.com/s/files/1/0430/9755/5093/files/jowixogo.pdf
    • https://cdn.shopify.com/s/files/1/0434/7058/6006/files/82776965148.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006e7f.bin
79d74fab53b944c3515121cd912be5c98e8000802d596f69373c7388ff3a3e7a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E7F 5560 bytes
font_01_sfnt_off00008152.bin
507ea6a008ab5070ec9bda6e85de23b05396e19eb752ba3aef97cc3b15ce2e7d
pdf-font-stream PDF embedded font (sfnt) at offset 0x8152 10316 bytes