Malicious PDF — malware analysis report

Static analysis result for SHA-256 623f2c42270a4ed8…

MALICIOUS

PDF

47.5 KB Created: 2020-08-24 04:07:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5f856aef87d52902df3a5fe8871d89cb SHA-1: 15684a76a95fcad30446a6c83bc13e08a092a377 SHA-256: 623f2c42270a4ed860b04c1da68fed2c7cdda16c4afb271e39ca5d5ea2a24bb2
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of embedded URLs, with one identified as a malicious redirector. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external PDF links, suggesting an attempt to manipulate search engine results or distribute further malicious content. While no scripts were explicitly extracted, the presence of embedded URLs and the ML classifier's high confidence suggest malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=real+essential+sheet+mask+collagen
    • http://vizopagod.settimocieloretreat.com/uploads/1/3/1/0/131070571/masexelad.pdf
    • http://gekik.joewoodmanwildlife.com/uploads/1/3/1/3/131381679/b7c553343.pdf
    • http://balad.adhdsolutionsforlife.com/uploads/1/3/1/6/131637136/8688288.pdf
    • http://dasomemiw.mdlashesllc.com/uploads/1/3/2/7/132741508/xevekebem_suwurediju.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0432/2993/7832/files/eminem_agent_contact_information.pdf
    • https://cdn.shopify.com/s/files/1/0433/6202/5624/files/23464312427.pdf
    • https://cdn.shopify.com/s/files/1/0432/1483/1780/files/lugiwej.pdf
    • https://cdn.shopify.com/s/files/1/0432/3845/7501/files/jibixiximero.pdf
    • https://cdn.shopify.com/s/files/1/0433/2758/6457/files/92855903006.pdf
    • https://cdn.shopify.com/s/files/1/0434/9722/6402/files/77168695540.pdf
    • https://cdn.shopify.com/s/files/1/0434/1887/8110/files/35989137727.pdf
    • https://cdn.shopify.com/s/files/1/0432/4504/3876/files/sistem_pencernaan_manusia_jurnal.pdf
    • https://cdn.shopify.com/s/files/1/0429/6923/5619/files/faderulanuf.pdf
    • https://cdn.shopify.com/s/files/1/0431/8819/1394/files/definition_of_qualitative_research.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000593b.bin
0d38fb7d659c1e30d95b0a25c197df1830438fa00eca5ee1b6371f22ddb03956
pdf-font-stream PDF embedded font (sfnt) at offset 0x593B 5188 bytes
font_01_sfnt_off00006ab4.bin
ad46f4648fe0d0f46fd9255d76087ea18cd9f5ecb093713eca4ae3edeebced26
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AB4 3128 bytes
font_02_sfnt_off000077ca.bin
239b8e0e8048bede40f07c0b99de99245f911ce9073b23dc24b45d03590d2df7
pdf-font-stream PDF embedded font (sfnt) at offset 0x77CA 10332 bytes
font_03_sfnt_off00009b34.bin
5ea7567cdbf98ba8c8897777593ace99eeb1c2989ccecea4e155e9cabcd72575
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B34 16276 bytes