Malicious PDF — malware analysis report

Static analysis result for SHA-256 8967e9e6135de71b…

MALICIOUS

PDF

43.5 KB Created: 2020-09-20 23:08:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5193ef7314a6598ea8059723c65a0a53 SHA-1: a93c24f0671503d660cafe23756ac9d521421864 SHA-256: 8967e9e6135de71b664f532a1522ead9a5577f148c342ee8f2720e6297b37d7c
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a significant number of embedded links, with heuristics indicating it is a link farm designed for SEO manipulation or malicious redirection. One critical heuristic identified a link to known malicious redirector infrastructure. While no scripts were extracted, the sheer volume of links and the ML classifier's high confidence suggest a malicious intent to lead users to harmful content or further stages of an attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=song+of+discord+3.5
    • http://nofesuji.amandabechtel.com/uploads/1/3/0/7/130739615/pifuru.pdf
    • http://kefetofo.stepin2myoffice.com/uploads/1/3/1/4/131438684/5ef8be41a45.pdf
    • http://files.amandacasale.com/uploads/1/3/1/8/131871740/8872462.pdf
    • http://files.owlacorn.com/uploads/1/3/0/8/130814630/7075609.pdf
    • http://tugufej.thebackyardsalad.com/uploads/1/3/0/7/130740221/2282036.pdf
    • http://barurati.jeff3danimation.com/uploads/1/3/0/8/130874299/zalopajeregimad.pdf
    • http://files.breadandbuttertogo.com/uploads/1/3/2/8/132815148/xumit.pdf
    • http://memopoxob.newlifefrostburg.com/uploads/1/3/1/1/131163616/fc338e.pdf
    • http://petuti.mayfieldwoodsorchestra.com/uploads/1/3/1/8/131856072/5882853.pdf
    • http://files.bittermansguide.com/uploads/1/3/0/7/130738993/7865249.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://9255b3fa-4b76-49c7-8e27-fe4e22635897.filesusr.com/ugd/0cd3a8_88426301c5944e608ec854ac92c23c26.pdf?index=true
    • https://87f4a9c4-f6fb-4074-8116-f6385d1c7ac4.filesusr.com/ugd/3f0e57_7405777509914e688853819927be76e4.pdf?index=true
    • https://40340982-4fab-4368-a00b-35057931d2ea.filesusr.com/ugd/03dcd4_e862a4a32af142c3a9cfc92f44c9d3e9.pdf?index=true
    • https://e112c01d-c9d3-4a29-ac34-7d3d63ddac11.filesusr.com/ugd/8c2e83_890e370beb7c4e39813396e3903aa862.pdf?index=true
    • https://254a4d98-acc5-4e56-8ff7-12e07477e4f7.filesusr.com/ugd/1a1092_bac77932391c4eafb1879963bebef7e2.pdf?index=true
    • https://ae9b54eb-ec1d-4de1-b514-79cfbb3bde4e.filesusr.com/ugd/5899d5_aad79a961f41410c8472f794ad526e8a.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006bb4.bin
54977743655a5c1045b801f1d345624835708329b2404e6ec7ee48b9bf3d5e62
pdf-font-stream PDF embedded font (sfnt) at offset 0x6BB4 5368 bytes
font_01_sfnt_off00007e1b.bin
8b22ff540e1af0538207d1c50b51f5a8f810ad2a32516421740f19da2bb7f7e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E1B 10328 bytes