Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3feeefe6cdbcedf…

MALICIOUS

PDF

85.6 KB Created: 2020-10-26 03:40:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: f40002dc3dd13367e4889afa007f1de8 SHA-1: 1dbd730d225726d4bfabf4962e98451b65a6b58e SHA-256: a3feeefe6cdbcedfa250c842b2f1dea9c2b64c4a1aeb818c57e93fef99657564
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm and routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=%25D8%25AA%25D8%25B9%25D8%25B1%25D9%258A%25D9%2581+%25D8%25A7%25D9%2584%25D8%25A3%25D8%25AF%25D8%25A7%25D8%25A1+%25D8%25A7%25D9%2584%25D8%25A3%25D9%2583%25D8%25A7%25D8%25AF%25D9%258A%25D9%2585%25D9%258A In PDF document text
    • https://cdn-cms.f-static.net/uploads/4366040/normal_5f88032d38002.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4392652/normal_5f8eebf6e711f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4372104/normal_5f893891aadbe.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/fe685d9e-4e1d-43bd-ae4c-b528ce2378bd/31363754112.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0494/1882/9991/files/it_gon_rain_family_guy_episode.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/7122/5502/files/jigeludiwawolozavafiwovim.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0478/8876/0998/files/husqvarna_riding_mower_repair_manual.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/3859/6511/files/lizard_virtual_lab_quiz_answers.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0428/8135/1839/files/2372003734.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d2a43b13-8ded-4b5b-9931-9d6a7e951a5a/fewibo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c762c111-4cf8-446d-9a3e-87babea3c159/gipuxadowobifabozevezek.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dca09aac-251e-45bc-b6ae-eafcb2a4b7c7/jemiralazumoridu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3693bb7b-e2a0-4896-96b1-69e2263e8766/35570394545.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f98184ca-976d-4c73-b369-d9101c317a78/nileze.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a63bdf08-23be-447b-be37-d25f39daded0/labatagujero.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/487fcd1e-3d5e-4d6a-ab14-67e67150e485/jawib.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/81311ded-77a8-4d20-ab64-3dda83105f24/18614167389.pdfIn PDF document text
    • https://s3.amazonaws.com/wilugugo/32349715986.pdfIn PDF document text
    • https://s3.amazonaws.com/gupuso/37132679229.pdfIn PDF document text
    • https://s3.amazonaws.com/figugipopar/cantico_delle_creature_branduardi.pdfIn PDF document text
    • https://s3.amazonaws.com/felasorarabipis/8918337763.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0000fe39.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xFE39 33284 bytes
SHA-256: 3ae4ac17bc68284de874890ad049f3e5ed0a54f14bc60a067f75a46bba9a176b
font_00_sfnt_off0000bc7e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBC7E 3396 bytes
SHA-256: 8ad2bb29851bdd7a5ab1ba16dfb395f1eec87213095ff6a7d7030976db4ad16e
font_01_sfnt_off0000c788.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC788 17604 bytes
SHA-256: 3875c3fd24c642718a3c7ede92895fb30195526bbac1d61323925fdfeffdac36
font_02_sfnt_off0000e241.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE241 8188 bytes
SHA-256: 18ea2b236cb0e1aca0902fb173a7a3e998134fe9e3ac88774856646f66d2b530
font_04_sfnt_off00013783.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13783 4324 bytes
SHA-256: 4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3