Malicious PDF — malware analysis report

Static analysis result for SHA-256 82196925c236b36c…

MALICIOUS

PDF

68.8 KB Created: 2020-11-04 10:02:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-15
MD5: f134a87b9af016acd8e54420cd8b3d6a SHA-1: a9a307ca72e6547100a1e4cc44a83766a0c39a55 SHA-256: 82196925c236b36c4840ca8f6485b25bed356e39be68b9e95fcdf1f4fa369c15
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with a critical heuristic identifying it as a redirector link to malicious infrastructure. The document body, though heavily obfuscated, contains a URL that appears to be part of this link farm. The presence of multiple external PDF links suggests an attempt to manipulate search engine results or direct users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/wb?keyword=methylene%20chloride%20structure In PDF document text
    • https://cdn-cms.f-static.net/uploads/4380881/normal_5f8f9aedd9791.pdfIn PDF document text
    • https://xemupawiked.weebly.com/uploads/1/3/4/3/134321325/sixiti.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4415073/normal_5f9b2c7b78a08.pdfIn PDF document text
    • https://detopeda.weebly.com/uploads/1/3/4/3/134305225/1776277.pdfIn PDF document text
    • https://baxovazexozubuv.weebly.com/uploads/1/3/4/3/134318553/128038.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4371787/normal_5f8e01ff8cfa0.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/58bd6e05-d6c1-4844-8c10-00cb5603f6a1/7235067557.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5d951ee6-6357-4a23-a9cc-809092c4faf9/tomisemuj.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f9721907-4897-49a1-a325-8c41fae5680d/51464862234.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f1056706-7519-4ebd-96f2-c3c7df5b1b0f/84890088015.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/93f07b86-740b-4890-8738-ae13547ad365/57055389817.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008e86.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8E86 6492 bytes
SHA-256: 0acae127d432746d095b5bd0375a0897f34f14d5dd3edc903598d39ab18e2e5d
font_01_sfnt_off00009e8a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9E8A 15252 bytes
SHA-256: ebc59f8420f0b6d34e347de892e724f4bf37b26380679c038d942aba49f021b0
font_02_sfnt_off0000cbc1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCBC1 4924 bytes
SHA-256: 2e166dc09bbbb2a4c75d6e091d0d324632bc4c36472639699144996a02b74bf8
font_03_sfnt_off0000dc8e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC8E 12412 bytes
SHA-256: c36685211d5b9d6cbc92a0b1e842cff47956a2d6bbb6eec614bc4a81a43891ec