Malicious PDF — malware analysis report

Static analysis result for SHA-256 6e1540dbb685f0c3…

MALICIOUS

PDF

42.2 KB Created: 2020-08-20 10:30:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9ff07105ddb9679cd308f09ca0955977 SHA-1: 788d12bc65664a720482eb6b559b11590a1990dd SHA-256: 6e1540dbb685f0c3bbffd2944ae9e3926af2e0fb484ee5af0f0908d676833bfb
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link that redirects to malicious infrastructure, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though heavily obfuscated, contains text related to "African animals videos" and a URL that appears to be part of a link farm. The presence of multiple embedded PDFs hosted on Shopify suggests an attempt to obscure the final malicious destination. No scripts were extracted, but the PDF structure itself facilitates the redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=african+animals+videos
    • http://zoleti.escapesdentaltv.com/uploads/1/3/0/7/130775726/gogenutopagesijin.pdf
    • http://xotut.ittakesavillageys.com/uploads/1/3/0/9/130969130/5053889.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0430/4296/3613/files/xowuvam.pdf
    • https://cdn.shopify.com/s/files/1/0432/0509/9675/files/8318739102.pdf
    • https://cdn.shopify.com/s/files/1/0439/9159/7214/files/gasitafulebitevejut.pdf
    • https://cdn.shopify.com/s/files/1/0430/8670/8893/files/munan.pdf
    • https://cdn.shopify.com/s/files/1/0440/4730/2806/files/36659452067.pdf
    • https://cdn.shopify.com/s/files/1/0430/0098/7801/files/2658590753.pdf
    • https://cdn.shopify.com/s/files/1/0432/0660/7012/files/bovazatevarupu.pdf
    • https://cdn.shopify.com/s/files/1/0431/4005/5208/files/blackjack_basic_strategy.pdf
    • https://cdn.shopify.com/s/files/1/0428/7037/4559/files/aerodrome_design_manual_part_7.pdf
    • https://cdn.shopify.com/s/files/1/0427/9740/0223/files/wedasafaju.pdf
    • https://cdn.shopify.com/s/files/1/0432/2626/7806/files/9766424859.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b45.bin
c3013014477d3213809630fe11beaca1042338f6e345092396c388270812774d
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B45 4924 bytes
font_01_sfnt_off00006bd4.bin
44804f21e957fe3fc78e4e890aaa25d39ad7609c666806febba63ed2ca28c686
pdf-font-stream PDF embedded font (sfnt) at offset 0x6BD4 9932 bytes
font_02_sfnt_off00008de0.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x8DE0 4324 bytes