Malicious PDF — malware analysis report

Static analysis result for SHA-256 72cc47dca66c1077…

MALICIOUS

PDF

32.2 KB Created: 2020-08-19 05:59:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3fdcdf0fe59df0bdfac62b3b5a23d697 SHA-1: b3c791967b533fd13673957a035c0b55f2ac73d9 SHA-256: 72cc47dca66c10775d3eb7e5aa7d5d5cb6cdf6b4cb57a976318248c83acaf27f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to external resources, including a known malicious redirector. The document body, though heavily obfuscated, contains a URL that appears to be a lure for users interested in 'dynamics crm 2016 virtual machine'. The presence of numerous links suggests an attempt to direct users to malicious sites or to generate traffic for SEO manipulation.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=dynamics+crm+2016+virtual+machine
    • http://files.b4birthdoula.com/uploads/1/3/2/3/132302924/fozoladof.pdf
    • http://dewodalu.groff4life.com/uploads/1/3/0/8/130815031/xaremozexojora_bubulerowote_kibibudag_baxokefijexova.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0435/0817/0918/files/g_d_a_full_form.pdf
    • https://cdn.shopify.com/s/files/1/0428/2885/7503/files/57752345600.pdf
    • https://cdn.shopify.com/s/files/1/0462/0232/3094/files/makita_circular_saw_track_guide.pdf
    • https://cdn.shopify.com/s/files/1/0431/7410/1160/files/ruxatosa.pdf
    • https://cdn.shopify.com/s/files/1/0428/8066/3705/files/nosoxolisebigela.pdf
    • https://cdn.shopify.com/s/files/1/0433/8312/8214/files/epidemiologia_basica_y_vigilancia_de_la_salud_modulo_4.pdf
    • https://cdn.shopify.com/s/files/1/0439/1842/6267/files/92597903654.pdf
    • https://cdn.shopify.com/s/files/1/0431/3769/5906/files/52516202649.pdf
    • https://cdn.shopify.com/s/files/1/0431/3848/2332/files/tecumseh_carburetor_identification.pdf
    • https://cdn.shopify.com/s/files/1/0436/0696/6430/files/jawewuzepivurenepazodo.pdf
    • https://cdn.shopify.com/s/files/1/0433/0982/6213/files/guvudoliguvora.pdf
    • https://cdn.shopify.com/s/files/1/0428/5267/9836/files/38341416169.pdf
    • https://cdn.shopify.com/s/files/1/0432/9252/4702/files/nopesexisovulo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004228.bin
aee1667a4fc91474886ba6eb13484d672dee74f8f2c3ac1a23f7a6437e8666e3
pdf-font-stream PDF embedded font (sfnt) at offset 0x4228 5680 bytes
font_01_sfnt_off0000555f.bin
18c2af0b65ee198fd2a5f612d8265ce53b5ee53be76b0731640511c06d7e5918
pdf-font-stream PDF embedded font (sfnt) at offset 0x555F 8908 bytes