Malicious PDF — malware analysis report

Static analysis result for SHA-256 76039e20af2260f6…

MALICIOUS

PDF

38.6 KB Created: 2020-08-21 16:12:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5be540380bde9a97b27947791920559e SHA-1: 464a94d83269286c539230f81d4d51f31269f4e9 SHA-256: 76039e20af2260f6bbecd9bbb9e493243aead56c3c42e4ecb3317b8811d536a6
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with one pointing to a known malicious redirector. The document also explicitly requests sensitive recovery secrets, indicating a phishing or social engineering attempt. While no scripts were directly extracted, the presence of embedded links and the nature of the request suggest an attempt to trick the user into divulging credentials or sensitive information.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=twitter+video+ios
    • http://tabolim.cprep.org/uploads/1/3/1/6/131606027/fudelupe.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0428/2331/9715/files/appointment_scheduling_app_android.pdf
    • https://cdn.shopify.com/s/files/1/0431/2665/3077/files/kelabasiwojokafipirata.pdf
    • https://cdn.shopify.com/s/files/1/0431/2432/6564/files/laxolegogesoxatonep.pdf
    • https://cdn.shopify.com/s/files/1/0431/3707/3314/files/54708502353.pdf
    • https://cdn.shopify.com/s/files/1/0434/8713/3860/files/estenosis_bilateral_de_la_arteria_renal.pdf
    • https://cdn.shopify.com/s/files/1/0429/1241/5907/files/wifemusemaz.pdf
    • https://cdn.shopify.com/s/files/1/0431/4431/5029/files/felawijawuboz.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/xizujebekox.pdf
    • https://cdn.shopify.com/s/files/1/0431/0673/0138/files/nifiz.pdf
    • https://twitter.com/PassengersMovie/status/821025484150423557
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b65.bin
03f72955c10f5faeaeef93273e69b721cbd4e789cd067b899888a31ffd8eb36f
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B65 4676 bytes
font_01_sfnt_off00006b6f.bin
cb7f66444f1da7161e0b8aa9e5e00fc9dce0978ebf3507948a0f53fbf9675da7
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B6F 10168 bytes