Malicious PDF — malware analysis report

Static analysis result for SHA-256 78130a9560108569…

MALICIOUS

PDF

62.2 KB Created: 2020-08-09 16:51:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c169e4e376bc1ae7ebb3468ad1dbe48b SHA-1: 553cf0197f00ba2165c919a776199f4a8004653d SHA-256: 78130a956010856930be49c0b57c94ce16227833b97077a8588db4767413d51d
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, with at least one identified as a malicious redirector. The ML classifier also strongly indicated maliciousness. This suggests the document is designed to lure users to external sites, potentially for phishing or to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=adversus+mathematicos+pdf
    • http://lopuwabuz.jennymills.co.uk/uploads/1/3/1/0/131070450/gawapalevuj-kotosusekojeka-siguwe.pdf
    • http://files.dorabramden.com/uploads/1/3/1/3/131382141/3729828.pdf
    • http://jawud.baytalmosul.com/uploads/1/3/0/8/130874359/9885738.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0432/1358/6600/files/viziwunekivawovoxitepixan.pdf
    • https://cdn.shopify.com/s/files/1/0433/9168/0666/files/greenhouse_gases_and_their_sources.pdf
    • https://cdn.shopify.com/s/files/1/0430/7727/1706/files/navy_pfa_calculator.pdf
    • https://cdn.shopify.com/s/files/1/0440/3901/2502/files/90937149485.pdf
    • https://cdn.shopify.com/s/files/1/0431/2068/9306/files/lomume.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/libuzab.pdf
    • https://cdn.shopify.com/s/files/1/0435/6371/2671/files/juruxenafe.pdf
    • https://cdn.shopify.com/s/files/1/0438/4056/9494/files/xomafedajemop.pdf
    • https://cdn.shopify.com/s/files/1/0434/0137/9996/files/97717150885.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009633.bin
ca7da0fb7785f7444b0d44c51b1032bdd6998b8e68ae373f22b9c613bc0b70a6
pdf-font-stream PDF embedded font (sfnt) at offset 0x9633 5188 bytes
font_01_sfnt_off0000a7d8.bin
85b0f17661f9530e35d1a484d3cee8d7f76e75d3af12bcc6360387a1b952fe34
pdf-font-stream PDF embedded font (sfnt) at offset 0xA7D8 18468 bytes
font_02_sfnt_off0000dddf.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDDF 4324 bytes