Malicious PDF — malware analysis report

Static analysis result for SHA-256 75b47bbb28706749…

MALICIOUS

PDF

161.9 KB Created: 2020-08-08 11:21:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4359a2bb3c219d61b377888c120cc4f4 SHA-1: 49c4ee034ce9c3a6e931d95879786f1a8f913a80 SHA-256: 75b47bbb287067490d4ef5cd270f4befcc3d82966e2ac08a04b3b30bae9a8cd6
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a link disguised as a free download for religious text, which redirects to a malicious URL. The ML classifier strongly flagged this PDF as malicious, and the embedded URL is associated with known redirector infrastructure. The document body, though heavily obfuscated, contains the malicious URL and text suggesting a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=bhagavad+gita+slokas+english+pdf+free+download
    • http://files.castlespacovers.com/uploads/1/3/0/8/130874067/zozila.pdf
    • http://files.bestillmove.com/uploads/1/3/1/4/131438692/feresiwololipazip.pdf
    • http://files.torontoflowergallery.com/uploads/1/3/1/4/131453555/8625456.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://cdn.shopify.com/s/files/1/0443/5968/0156/files/astigmatic_fan_test.pdf
    • https://cdn.shopify.com/s/files/1/0431/2717/7365/files/10966238513.pdf
    • https://cdn.shopify.com/s/files/1/0432/6352/5029/files/97418473885.pdf
    • https://cdn.shopify.com/s/files/1/0430/7045/5957/files/zerazokuven.pdf
    • https://cdn.shopify.com/s/files/1/0428/3770/4867/files/american_english_file_3_vk.pdf
    • https://cdn.shopify.com/s/files/1/0438/7792/5019/files/62053065924.pdf
    • https://cdn.shopify.com/s/files/1/0437/9967/5040/files/dufozigokod.pdf
    • https://cdn.shopify.com/s/files/1/0430/0469/0581/files/4795581672.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/73930450062.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00021b64.bin
fef700a898913e66f420f89c05095c540d217425a3ab5b3fad976b90a1311305
pdf-font-stream PDF embedded font (sfnt) at offset 0x21B64 5568 bytes
font_01_sfnt_off00022e69.bin
eb903a4bcabb0673128613fc2c6a3b3be6b6be0204d11159aa2f590e1d82ee93
pdf-font-stream PDF embedded font (sfnt) at offset 0x22E69 3740 bytes
font_02_sfnt_off000239e2.bin
3cff104846b3e3d6b0fcebe67ecf1fc95a5dc41b6148b20e739860647dc59a9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x239E2 12724 bytes
font_03_sfnt_off000261fe.bin
600a9df945b375c69d0fc40edd794eb86ad4ff8d68d3292abadd4199861cd84d
pdf-font-stream PDF embedded font (sfnt) at offset 0x261FE 6672 bytes