Malicious PDF — malware analysis report

Static analysis result for SHA-256 62660c2002fd8e8f…

MALICIOUS

PDF

53.2 KB Created: 2020-08-15 05:02:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: deecc9986552cf4a7840a529e05365b8 SHA-1: 45634971c6b3e14b8d166e603b37049b75cea504 SHA-256: 62660c2002fd8e8f34746503ae6f8b31a286450c23b4d9592a5f860abe707065
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of embedded URLs, with one identified as a malicious redirector. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, suggesting an attempt to manipulate search engine results or lead users to malicious content. The ML classifier strongly flagged this PDF as malicious, supporting the conclusion that it is designed for malicious redirection or SEO spam.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=tesla+model+3+performance+mit+anh%25C3%25A4ngerkupplung
    • http://files.mysportsmemory.com/uploads/1/3/2/6/132681482/4041562.pdf
    • http://files.keyspeechtherapy.com/uploads/1/3/1/3/131378990/kiradobud_modawatibad.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0432/1637/1867/files/25031809886.pdf
    • https://cdn.shopify.com/s/files/1/0429/9846/4661/files/fikoseluxojitel.pdf
    • https://cdn.shopify.com/s/files/1/0431/0922/0501/files/padunudowobapidefetes.pdf
    • https://cdn.shopify.com/s/files/1/0436/2698/7680/files/sulamoke.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/69296453687.pdf
    • https://cdn.shopify.com/s/files/1/0432/1270/1854/files/78662649368.pdf
    • https://cdn.shopify.com/s/files/1/0439/0807/1576/files/apocrypha_bible.pdf
    • https://cdn.shopify.com/s/files/1/0438/9447/2856/files/94307203324.pdf
    • https://cdn.shopify.com/s/files/1/0430/3034/7938/files/moponebur.pdf
    • https://cdn.shopify.com/s/files/1/0437/6467/8807/files/10907993653.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008ad5.bin
5a8093126df9da4255616f52521ed5386d0064ce2094e944c2b746e485d1cd42
pdf-font-stream PDF embedded font (sfnt) at offset 0x8AD5 5984 bytes
font_01_sfnt_off00009e76.bin
d5c62eb978f9fab56faf530ecb4bd4205e4d0d99d8a9cfd4e4353a66b2f897bd
pdf-font-stream PDF embedded font (sfnt) at offset 0x9E76 11980 bytes