Malicious PDF — malware analysis report

Static analysis result for SHA-256 6030e3afc30814dd…

MALICIOUS

PDF

46.9 KB Created: 2020-08-20 20:47:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 210e0eedafe3979d9d14f054f9b9aed4 SHA-1: d7a5363c1ef5cc7f124af31dc4a5818ed00da55b SHA-256: 6030e3afc30814dde2332f5d0e34eed2a810c57ede48121265fccd47e4782b02
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links and text that mimic a software download lure for 'Whatsapp for computer windows 7 ultimate'. One of the primary links directs to a known malicious redirector, indicating a phishing or malware distribution attempt. The presence of numerous other PDF links suggests a link farm or SEO poisoning tactic to increase visibility of the malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=whatsapp++for+computer+windows+7+ultimate
    • http://dikabug.vintuitivewmt.com/uploads/1/3/1/6/131636612/fewakobolodamuw_miledo_xexumir_pesuv.pdf
    • http://xezavip.servicetrackandfield.com/uploads/1/3/1/4/131454057/kugol-redixeva.pdf
    • http://dodajoz.negindastgheib.com/uploads/1/3/1/4/131408738/dotarod_tedeto_nimegevipuwu_ruzubeni.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0431/7901/6360/files/govepemexenoxigakaxom.pdf
    • https://cdn.shopify.com/s/files/1/0427/7554/3964/files/raleretekaluzowarizesuke.pdf
    • https://cdn.shopify.com/s/files/1/0434/1291/4332/files/jesus_song_aradhana_stuti_aradhana_free.pdf
    • https://cdn.shopify.com/s/files/1/0435/2717/6344/files/benefits_of_learning_english.pdf
    • https://cdn.shopify.com/s/files/1/0430/8893/7120/files/bacterial_cell_structure_and_function.pdf
    • https://cdn.shopify.com/s/files/1/0430/0426/4601/files/dokivaxuzonofa.pdf
    • https://cdn.shopify.com/s/files/1/0436/3000/2336/files/algebra_and_trigonometry_book_2.pdf
    • https://cdn.shopify.com/s/files/1/0431/4379/0760/files/64164538534.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/30552771564.pdf
    • https://cdn.shopify.com/s/files/1/0439/0692/4712/files/kaboridedekon.pdf
    • https://cdn.shopify.com/s/files/1/0429/7578/9215/files/59967470428.pdf
    • https://cdn.shopify.com/s/files/1/0438/8909/8907/files/serie_a_calendario_julho_download.pdf
    • https://cdn.shopify.com/s/files/1/0432/5975/6708/files/55013767736.pdf
    • https://cdn.shopify.com/s/files/1/0437/7804/8161/files/7414121239.pdf
    • https://cdn.shopify.com/s/files/1/0434/5122/0134/files/android_messages_change_color.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ec5.bin
334d3f6a9c67cd5db04c5e908348b0960ab3d9aabe5b44c41125dcbefcfc0058
pdf-font-stream PDF embedded font (sfnt) at offset 0x6EC5 5580 bytes
font_01_sfnt_off000081bc.bin
5ade036deb5ed7781324c8d5333573cc52f5c7c06b02ca060addabda28e9f908
pdf-font-stream PDF embedded font (sfnt) at offset 0x81BC 14132 bytes