Malicious PDF — malware analysis report

Static analysis result for SHA-256 6734162ff39a7e0d…

MALICIOUS

PDF

39.0 KB Created: 2020-08-01 22:57:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8a357cd5d84cd9c0caef5d3a5e5bd13d SHA-1: fe88b8d44358b3d323390341fcc03cb056b45f58 SHA-256: 6734162ff39a7e0d006f6993a864a934167c67e4ef16f51f23309f877c0e6d3f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, with one identified as a malicious redirector. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains the malicious URL, suggesting the primary purpose is to lure users to malicious sites, likely for SEO spam or phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=war+zone+damocles+kauyon+pdf
    • http://files.forasong.org/uploads/1/3/1/3/131382113/ad0b7a0c8.pdf
    • http://files.researchjunction.net/uploads/1/3/0/9/130970009/fapubarowi.pdf
    • http://files.bcmediaphotos.com/uploads/1/3/2/6/132682039/jajufosox_dofapezunemaxop_fufuribudob_dulomoj.pdf
    • http://files.mrsgreenger.com/uploads/1/3/0/9/130969659/gonelag-kibewofu-keguvaxusatawu-xodotesedoza.pdf
    • http://files.acelebrantinfrance.com/uploads/1/3/1/3/131398479/kaworusixoro_zozelanu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0437/8086/6197/files/58762062833.pdf
    • https://cdn.shopify.com/s/files/1/0432/9468/7400/files/70357649342.pdf
    • https://cdn.shopify.com/s/files/1/0429/9954/6010/files/17628274246.pdf
    • https://cdn.shopify.com/s/files/1/0437/5802/6904/files/47899839983.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/wadilizesiwegokadokepub.pdf
    • https://cdn.shopify.com/s/files/1/0428/8941/2767/files/60477729124.pdf
    • https://cdn.shopify.com/s/files/1/0429/8145/8069/files/jebuxidil.pdf
    • https://cdn.shopify.com/s/files/1/0430/8438/2357/files/resamudatofininikutazox.pdf
    • https://cdn.shopify.com/s/files/1/0435/1678/8900/files/zitavelesidev.pdf
    • https://cdn.shopify.com/s/files/1/0430/9945/5642/files/17967688814.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004ca7.bin
c6940675a444217a595236cb4dcf4807394ecb912ffe3a6d8b25d94a5efc83df
pdf-font-stream PDF embedded font (sfnt) at offset 0x4CA7 5284 bytes
font_01_sfnt_off00005e9f.bin
d1eb08a2e7816315f129ae4a10d836d59d75907b8118a2c340cc5f487ea1918d
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E9F 10012 bytes
font_02_sfnt_off000080b4.bin
ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230
pdf-font-stream PDF embedded font (sfnt) at offset 0x80B4 4324 bytes