Malicious PDF — malware analysis report

Static analysis result for SHA-256 9126d72ea29c5742…

MALICIOUS

PDF

34.7 KB Created: 2020-10-27 18:03:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 91d0d0730baaf228dfb65844b2fa89f1 SHA-1: 7d7cdd30f447a0debc804306e53c667da1f7c263 SHA-256: 9126d72ea29c574204e5ef4207f1e70742d37fc1eb76374624922195fc585bd1
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to a link farm designed to host SEO-optimized content. One prominent link redirects to a known malicious infrastructure, likely intended to deliver a secondary payload or phish users. The document body itself contains text related to a game and the redirector URL, suggesting a lure to entice clicks.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=earn+to+die+part+3+hacked+unblocked
    • https://cdn-cms.f-static.net/uploads/4374188/normal_5f8ed6d711b95.pdf
    • https://cdn-cms.f-static.net/uploads/4377647/normal_5f8bd8994e979.pdf
    • https://cdn-cms.f-static.net/uploads/4379849/normal_5f90989c0ca68.pdf
    • https://cdn-cms.f-static.net/uploads/4366956/normal_5f92c35b57b56.pdf
    • https://cdn-cms.f-static.net/uploads/4369514/normal_5f88f18c25388.pdf
    • https://cdn-cms.f-static.net/uploads/4374839/normal_5f97e6b92d46e.pdf
    • https://cdn-cms.f-static.net/uploads/4403673/normal_5f912d038de22.pdf
    • https://cdn-cms.f-static.net/uploads/4366628/normal_5f876de4bad3f.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/memul/logic_gate_table.pdf
    • https://s3.amazonaws.com/fasanag/xudovilidu.pdf
    • https://s3.amazonaws.com/desenaz/tavom.pdf
    • https://s3.amazonaws.com/mijedusovineti/asvab_practice_test_2018.pdf
    • https://s3.amazonaws.com/limewub/jack_and_the_beanstalk_story_with_pictures.pdf
    • https://cdn.shopify.com/s/files/1/0439/1570/6523/files/isp_decimator_manual.pdf
    • https://cdn.shopify.com/s/files/1/0441/2047/3752/files/63313569344.pdf
    • https://cdn.shopify.com/s/files/1/0502/6814/3798/files/android_9.1_mobile_phones.pdf
    • https://cdn.shopify.com/s/files/1/0433/0219/1269/files/bivowowejelezifewaredijon.pdf
    • https://cdn.shopify.com/s/files/1/0483/4695/5927/files/yoshi_and_birdo_gender.pdf
    • https://cdn.shopify.com/s/files/1/0483/9440/4008/files/kinalofegawomadu.pdf
    • https://cdn.shopify.com/s/files/1/0498/6080/4770/files/pokemon_go_spoof_android_download.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006c01.bin
1a9c00c03cf1c26917d7d0a59fa2d834d8389cb8398568b283bd606813481e46
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C01 5308 bytes