Malicious PDF — malware analysis report

Static analysis result for SHA-256 8911f51b581838d9…

MALICIOUS

PDF

137.6 KB Created: 2020-11-01 04:58:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1c580691a2b104e48942879a7210f76a SHA-1: 04d0ae3c10c19c64cf563cc695855684643448b6 SHA-256: 8911f51b581838d9c214f338ab4d3669a0bc870c59235b0bae174b9dd0ac7d79
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to Weebly-hosted files, and one directly to a known malicious redirector. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to potentially harmful external sites, likely for further exploitation or phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9171

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=american+and+national+identity+apush+period+1
    • https://mokekisinuru.weebly.com/uploads/1/3/4/3/134366850/dojiwalul_dirak_kafetolatimim_wasegukozubeb.pdf
    • https://fidevawane.weebly.com/uploads/1/3/0/8/130814252/6350326.pdf
    • https://gulemexaw.weebly.com/uploads/1/3/4/3/134360266/1821568.pdf
    • https://redunexodozik.weebly.com/uploads/1/3/0/8/130814050/valiwadelel.pdf
    • https://famonusowofem.weebly.com/uploads/1/3/4/3/134349488/dukuxoxusapev-nimejufososube-fejusitenev-bamukizabojofu.pdf
    • https://laxuruvu.weebly.com/uploads/1/3/1/4/131482832/tidabunaroto-pobitojezos-detobisosujiw.pdf
    • https://cdn-cms.f-static.net/uploads/4382190/normal_5f8facc2c8f95.pdf
    • https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/6ec94.pdf
    • https://kusebedanosude.weebly.com/uploads/1/3/1/1/131163667/7580225.pdf
    • https://nigupisotaku.weebly.com/uploads/1/3/4/3/134374455/5fc96de72036.pdf
    • https://naxedomabaxa.weebly.com/uploads/1/3/1/6/131606472/kulezewutabutitew.pdf
    • https://sutogibigasoju.weebly.com/uploads/1/3/1/0/131070189/1d5c337ddc9c20.pdf
    • https://lixaworone.weebly.com/uploads/1/3/1/8/131871871/kadijafapesu_donasim_juwam.pdf
    • https://sonotipudo.weebly.com/uploads/1/3/4/3/134326760/warabamu_rosumomomoj_jusuzup_zuritar.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fea7.bin
fb8a74844dc940836aa205e7f5fce78c2a584cfcf413cf408de1ca29204b55f2
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEA7 7260 bytes
font_01_sfnt_off00011144.bin
8627e75055aa90ae72c661c25ab6081395ded9d6f1c42514b5848c0b7aa4f925
pdf-font-stream PDF embedded font (sfnt) at offset 0x11144 5456 bytes
font_02_sfnt_off000123ac.bin
4be87eda0f10ee5819dfb942214542a083c7aab9097f13507bad5b7878567f57
pdf-font-stream PDF embedded font (sfnt) at offset 0x123AC 63848 bytes
font_03_sfnt_off0001d02e.bin
e2f24fd58ae7f87dda894c987d93fb15afd9ca3566cb5ba56734c4cd576b0526
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D02E 11068 bytes
font_04_sfnt_off0001f60b.bin
0bfaed939ec0cd146a8efd8c2dd4506a31df9de7e9073b73f9971d1ca2666a41
pdf-font-stream PDF embedded font (sfnt) at offset 0x1F60B 20120 bytes
font_05_sfnt_off0002184e.bin
fc9aa48e79ccc6e0f914b4748175334026105657c0013aac1cfefd8d71ef0bcc
pdf-font-stream PDF embedded font (sfnt) at offset 0x2184E 1748 bytes