Malicious PDF — malware analysis report

Static analysis result for SHA-256 73bf1a8b4914e394…

MALICIOUS

PDF

40.3 KB Created: 2020-08-15 02:58:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b79e914961e56a1a4fc569e3026e220e SHA-1: 813712589e2070f2e5cdd07e2f8524c0564d101d SHA-256: 73bf1a8b4914e394da5d4737db5ef5850b8f07394d7bfeedf1fb6201b7e5dd2a
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links to other PDF files, a technique often used to create SEO spam or to obscure malicious redirects. One of the primary links points to a known malicious redirector infrastructure. The ML classifier also strongly indicated maliciousness. While no scripts were directly extracted, the structure and embedded links suggest an attempt to lure users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=hsk%201%20book%20pdf
    • http://files.kuepferenterprisesroofing.com/uploads/1/3/2/3/132303410/potagutigab.pdf
    • http://files.mariosmathtutoring.com/uploads/1/3/1/4/131453682/6e79b55e183.pdf
    • http://files.redmoonbronxsoapsandteas.com/uploads/1/3/0/9/130970022/0c57c5a6ef9afd5.pdf
    • http://files.ashraeli.com/uploads/1/3/1/4/131406478/4674537.pdf
    • http://ridativoj.dhsupwardbound.com/uploads/1/3/0/9/130968926/sufakix.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0430/9054/2741/files/payroll_accounting_book.pdf
    • https://cdn.shopify.com/s/files/1/0431/0391/2098/files/lusoxififarirema.pdf
    • https://cdn.shopify.com/s/files/1/0436/5287/4390/files/lewizenereta.pdf
    • https://cdn.shopify.com/s/files/1/0435/1036/6362/files/24735003857.pdf
    • https://cdn.shopify.com/s/files/1/0431/0201/1548/files/vewamamavosu.pdf
    • https://cdn.shopify.com/s/files/1/0430/5725/0455/files/waweka.pdf
    • https://cdn.shopify.com/s/files/1/0435/3789/1477/files/nirotinuva.pdf
    • https://cdn.shopify.com/s/files/1/0430/6658/9335/files/simplifying_algebraic_expressions_puzzle.pdf
    • https://cdn.shopify.com/s/files/1/0439/4693/4430/files/49107867612.pdf
    • https://cdn.shopify.com/s/files/1/0435/9516/9950/files/9287882285.pdf
    • https://cdn.shopify.com/s/files/1/0436/9163/8934/files/watch_superbad_123movies.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006075.bin
0ae730f2a63fc463b9e72033ea2d45fdce2a34b3a82167a9e7b03ddf7de20fcc
pdf-font-stream PDF embedded font (sfnt) at offset 0x6075 4912 bytes
font_01_sfnt_off0000713c.bin
a8025175136752d3bea7e80838725f779c4bc713681447f74e7b4de87d796b16
pdf-font-stream PDF embedded font (sfnt) at offset 0x713C 10348 bytes