Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8f34bbdfab49532…

MALICIOUS

PDF

32.6 KB Created: 2020-09-20 01:43:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 36c34a722ea2b6fed35b155b97f5729d SHA-1: 7da69b4ef8074a584fce28423ee04032c937e2ba SHA-256: a8f34bbdfab4953218d8da47504c9fef2f5d68ab703adc298723377046b62660
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a malicious redirector link disguised with a lure about Prince concerts. This link leads to a link farm of numerous other PDF documents, indicating a coordinated effort to distribute content through a network of redirectors and hosted files. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=prince+concerts+in+atlanta
    • http://sutuvar.pcgeeksonthego.com/uploads/1/3/2/3/132302720/e15f5.pdf
    • http://ratevov.enactusguelph.ca/uploads/1/3/1/1/131164239/tebevi_bivunozipewuwaz_meputoba.pdf
    • http://noximug.linie-e.com/uploads/1/3/0/7/130739377/taxarujeza-kuduku-jodipelexofatux.pdf
    • http://xasokilar.mikeharrisdesign.net/uploads/1/3/1/6/131636665/86d077.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/68769425665.pdf
    • https://cdn.shopify.com/s/files/1/0430/6986/6141/files/varasivixaganibogutore.pdf
    • https://cdn.shopify.com/s/files/1/0430/5548/0981/files/fisica_atomica_y_molecular.pdf
    • https://a9acbccc-7893-49f6-96ca-fd4d798bdfb0.filesusr.com/ugd/bc84a3_a6c2f80457ae4852bed87e85296d94cf.pdf?index=true
    • https://5cf9e869-a451-4fe4-927c-43c12e8ff72d.filesusr.com/ugd/b3318b_fc8796623fe1476aa862f1113b14980b.pdf?index=true
    • https://0cd7cc6f-edf5-4afb-ad5d-6d2d5c105ab0.filesusr.com/ugd/1cc7e8_bf0e33ba4f4e4db8a02a861c63fc0bda.pdf?index=true
    • https://01e9c1c1-69cc-40d4-8971-08f65d73a734.filesusr.com/ugd/a382ee_892f5bd439e44345a0bfffd67eae248b.pdf?index=true
    • https://d67302e5-4c39-42ac-ba0b-fb65de753d8d.filesusr.com/ugd/f91cf1_e892e85ac8a54975ba09686507f6b80d.pdf?index=true
    • https://fbab0a7a-a9e4-4641-83a7-127d35be8cfa.filesusr.com/ugd/f68081_eda5aaa5b6c1453cb992d1888eca2478.pdf?index=true
    • https://56f4de74-18f6-4d27-87d7-b97ccdb42999.filesusr.com/ugd/dfb5f8_e0943bbbfdb040558351040921536232.pdf?index=true
    • https://505e4a3f-da3b-4666-93cf-5bd05be84383.filesusr.com/ugd/17159d_83018becf6ed405b91372ce3c2c64799.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://505e4a3f-da3b-4666-93cf-5bd05be84383.filesusr.com/ug

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004550.bin
e5b49ec87d884068b668cd36b14000d558194d94597d22ea792f344c44b0d207
pdf-font-stream PDF embedded font (sfnt) at offset 0x4550 4792 bytes
font_01_sfnt_off000055a6.bin
95d52d6611ada5c3eaaa21439ff73daf8358425e875da897e1b1233b54a39fe8
pdf-font-stream PDF embedded font (sfnt) at offset 0x55A6 9416 bytes