Malicious PDF — malware analysis report

Static analysis result for SHA-256 a1a6bf8b58c7fd71…

MALICIOUS

PDF

38.0 KB Created: 2020-07-08 19:09:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1149536052c22780b21fdc7e27b7df25 SHA-1: 5c7b19efca33c03adc11129fdf33ea4eaa18c776 SHA-256: a1a6bf8b58c7fd7116862bbda8cd8c585b9963aeb25e79fe7461126ec58e33a4
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, many of which point to external PDF files. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK indicates that at least one of these URLs leads to known malicious infrastructure. The document body text, though partially corrupted, includes the string 'Manual grrf eletronica 2017' and several URLs, reinforcing the idea that the document is a lure. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=manual%20grrf%20eletronica%202017
    • http://files.unityofpalmyra.org/uploads/1/3/0/7/130775827/0d2098eedc2.pdf
    • http://files.renndrive.com/uploads/1/3/1/6/131637919/notusepoveb.pdf
    • http://files.frufruandfeathers.com/uploads/1/3/0/7/130739183/34486212.pdf
    • http://files.oikstrategy.com/uploads/1/3/1/4/131406433/pelijabuvik-kunipija-novivegome-xikejiza.pdf
    • http://files.pennybrittenphotography.com/uploads/1/3/0/8/130874495/5243647.pdf
    • http://files.whistlingfrogresort.com/uploads/1/3/2/6/132681002/masaberilanimubaloji.pdf
    • https://tidulijewiso.files.wordpress.com/2020/06/pirixilefejid.pdf
    • https://tamanalewoja.files.wordpress.com/2020/07/dawav.pdf
    • https://fufegolakod124143400.files.wordpress.com/2020/06/kegaguwipefetije.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/84574839703.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/duwaxufezemurogagur.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/sopituwoxo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000052b2.bin
3d20137acb9e00a5af44d3c2731606a8de0e8e78d1befb9d1bdd3c6a2d90651d
pdf-font-stream PDF embedded font (sfnt) at offset 0x52B2 5164 bytes
font_01_sfnt_off00006460.bin
2736cac44d10ee64b398b001df198f20ea4c3ba8f5e7e0d05aed3a6cd5147570
pdf-font-stream PDF embedded font (sfnt) at offset 0x6460 12348 bytes