Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f36f740db5dbe36…

MALICIOUS

PDF

49.2 KB Created: 2020-11-08 02:16:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 25669952a7c601f149e49b61291ed7b0 SHA-1: 1b6d0c7979bfbd4909caaeae5563c2ce7dd20cf6 SHA-256: 9f36f740db5dbe367392cf730301a55d8a7be29ea75cd5b3e930ccf4fca889ce
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous embedded links, with one pointing to a suspicious URL that appears to be part of a link farm or SEO manipulation scheme. The ML classifier strongly indicated maliciousness, and the presence of many external links suggests an attempt to redirect the user to potentially harmful content or to improve search engine ranking for malicious sites. No scripts were extracted, but the PDF structure itself is used to host and distribute these links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/aws?keyword=watch+cartoons+online+tv%252Fninjago
    • https://cdn-cms.f-static.net/uploads/4447487/normal_5f9f912ae7a98.pdf
    • https://buxiniti.weebly.com/uploads/1/3/4/3/134309366/6794538.pdf
    • https://cdn-cms.f-static.net/uploads/4370777/normal_5f88a410e1b95.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://gogajajar.files.wordpress.com/2020/11/48539197016.pdf
    • https://vabavoresadi.files.wordpress.com/2020/11/converter_word_trackidsp-006.pdf
    • https://bagiwes.files.wordpress.com/2020/11/library_information_ielts_listening_test_answers.pdf
    • https://s3.amazonaws.com/jadudusujuje/kavazumunexuwokefunaberon.pdf
    • https://s3.amazonaws.com/wazotojemov/zerakupibiraluwod.pdf
    • https://xoxedoxiki.files.wordpress.com/2020/11/43220934598.pdf
    • https://s3.amazonaws.com/suxiweke/vedajutotux.pdf
    • https://tidesefotiku.files.wordpress.com/2020/11/convert_word_to_fillable_online.pdf
    • https://galitedavaku.files.wordpress.com/2020/11/nojunomovi.pdf
    • https://s3.amazonaws.com/tosasugokod/pifijoxuxok.pdf
    • https://s3.amazonaws.com/zunaduxa/11257480586.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000073ec.bin
c885e92fe9abcebbd175e81d921a8b716a5a98cbf244d187f1f2ffb4958388cf
pdf-font-stream PDF embedded font (sfnt) at offset 0x73EC 5036 bytes
font_01_sfnt_off00008514.bin
9735aa0731a7c41562efabf333690d3bcf3f0571477f6bbb35cdc3470493d6bd
pdf-font-stream PDF embedded font (sfnt) at offset 0x8514 10864 bytes
font_02_sfnt_off0000aa09.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0xAA09 4324 bytes