Malicious PDF — malware analysis report

Static analysis result for SHA-256 7005511e9010773c…

MALICIOUS

PDF

40.6 KB Created: 2020-08-18 15:13:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dfce168934f35b66bc036e0924498e58 SHA-1: 573845ed2da1dd3e0a6ea32b46c45f2069b5a4a3 SHA-256: 7005511e9010773c8414f3d8a7570f97d078d2aa91925e345b8ad629155557fe
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm and a redirector URL pointing to malicious infrastructure, suggesting a phishing or scam attempt. The presence of a 'download' button lure reinforces this. Although no scripts were explicitly extracted, the PDF structure and embedded links are indicative of malicious intent, likely to lead the user to download further malware or engage in fraudulent activity.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=counter+strike++free+warzone
    • http://files.theblueeyeddaisy.com/uploads/1/3/0/8/130873855/tinimopoxusunot-romepisode-gibare-biwoj.pdf
    • http://files.justanotherflutist.com/uploads/1/3/1/6/131606392/924543.pdf
    • http://files.yourbritvoice.com/uploads/1/3/0/7/130738943/darawinuf.pdf
    • http://guruwigi.14barreldesigns.com/uploads/1/3/1/4/131437812/mesewosigoj.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0463/1330/8325/files/community_hours_sheet_yrdsb.pdf
    • https://cdn.shopify.com/s/files/1/0433/2093/4558/files/1991_chevrolet_caprice_classic_manual.pdf
    • https://cdn.shopify.com/s/files/1/0439/6482/5758/files/sapafemexidoxupa.pdf
    • https://cdn.shopify.com/s/files/1/0433/5455/4533/files/asme_y14_5m_2020_download.pdf
    • https://cdn.shopify.com/s/files/1/0430/6731/0231/files/gakisefivusaxij.pdf
    • https://cdn.shopify.com/s/files/1/0429/2742/3654/files/venifulonowoxu.pdf
    • https://cdn.shopify.com/s/files/1/0429/2762/0249/files/java_foundations_3rd_edition_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/5399/8487/files/wuvepakukuj.pdf
    • https://cdn.shopify.com/s/files/1/0437/0278/0057/files/simile_and_metaphor_worksheet_grade_4.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006146.bin
4373c5bbd7b635a3fbc18e081b6b15a6a3ff0daa6da474c2d6c5da729b949623
pdf-font-stream PDF embedded font (sfnt) at offset 0x6146 4840 bytes
font_01_sfnt_off000071e6.bin
c518b4b7fd8bf5b07000af6bb3941d85a5dd36c722502d73585361e877aa8dce
pdf-font-stream PDF embedded font (sfnt) at offset 0x71E6 10628 bytes