Malicious PDF — malware analysis report

Static analysis result for SHA-256 71c41eaf2330ca23…

MALICIOUS

PDF

46.3 KB Created: 2020-08-14 02:52:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 088988518b90ef4891f7b711720e5c2d SHA-1: e06b2b9ff253600cd270814bc0151670273d79ab SHA-256: 71c41eaf2330ca238091031c3a6bded74eb974eae47fc577db9170b03679524c
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous embedded links, with one identified as a malicious redirector. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, suggesting a tactic to drive traffic to potentially malicious sites. The ML classifier also strongly flagged this PDF as malicious. The embedded URLs likely serve as the primary mechanism for directing users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=imperialismus%20unterrichtsmaterial%20pdf
    • http://files.saygereviews.com/uploads/1/3/1/0/131070294/1778516.pdf
    • http://files.indianasal.org/uploads/1/3/0/8/130874567/xilif-kevojurine-levozejife-ronuxuk.pdf
    • http://files.tudublinsummerschool.com/uploads/1/3/0/9/130969639/lojegi_sidudozule.pdf
    • http://zudevox.zachzaitlin.com/uploads/1/3/1/4/131406717/vupiguma_zikizi_figose.pdf
    • http://files.makingsiliconebabies.com/uploads/1/3/2/8/132814375/4076558.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/fejatomamegebuwugibuvu.pdf
    • https://cdn.shopify.com/s/files/1/0438/2916/6242/files/pokemon_gold_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/6499/1637/files/48477514410.pdf
    • https://cdn.shopify.com/s/files/1/0428/5225/3863/files/40439482249.pdf
    • https://cdn.shopify.com/s/files/1/0437/6225/3982/files/remove_white_background_from_illustrator.pdf
    • https://cdn.shopify.com/s/files/1/0433/0677/8777/files/spanish_adjectives_list_a_z.pdf
    • https://cdn.shopify.com/s/files/1/0433/6661/3141/files/76272699808.pdf
    • https://cdn.shopify.com/s/files/1/0435/4995/0111/files/18632423094.pdf
    • https://cdn.shopify.com/s/files/1/0432/5123/7022/files/benoit_mandelbrot.pdf
    • https://cdn.shopify.com/s/files/1/0435/1007/1460/files/rxprep_2018_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0435/9382/6463/files/23324288144.pdf
    • https://cdn.shopify.com/s/files/1/0437/2358/7736/files/pifuta.pdf
    • https://cdn.shopify.com/s/files/1/0431/0417/4233/files/jigekanador.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005f91.bin
d00566c40777b0c964844a2b4306371dc2f867c7e75ec13fbfafbe505e3cc640
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F91 5332 bytes
font_01_sfnt_off00007176.bin
248851eb19964914907dc2505aebc4c50b5b0e9cb8bad7f68a98ef237665b03a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7176 10852 bytes
font_02_sfnt_off00009552.bin
0b4bdbf031826b8fe301f8b6a8a1f26a7af7d7ba100a217828ecbf7a6979f704
pdf-font-stream PDF embedded font (sfnt) at offset 0x9552 16076 bytes