Malicious PDF — malware analysis report

Static analysis result for SHA-256 af5099e32859a7b2…

MALICIOUS

PDF

52.0 KB Created: 2020-10-31 00:51:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-15
MD5: 01ffbb92d17066949325939d8e047cd5 SHA-1: e2716ab71b342f0beb951b612c79cdd09ce4590b SHA-256: af5099e32859a7b2e174b2712e4025fe478a84ed38794dcbe5fe76c130558e15
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF was flagged for containing links to known malicious redirector infrastructure and for being part of a link farm. The document body contains obfuscated text and a URL pointing to a malicious redirector. While no scripts were directly extracted, the PDF structure and embedded links strongly suggest an intent to redirect users to malicious sites, likely as part of a phishing or malware distribution campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/123?keyword=the+jade+peony+free+pdf In PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/3eec6724-56ad-4302-bb46-ef07f6fb8d89/winusb_maker_zotac.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e527f045-44d7-4e0a-aee2-d2ae7aad71ee/7638946408.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/12099e8f-becd-4494-a4cf-0ccc38bfd954/josafawapix.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/73aa26e3-bd80-48e1-8559-6291cdcc6a9c/92817096207.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c00740d6-89a9-4a00-a9cb-2b8bc3501ef4/sojirine.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6624c94e-1424-45e8-ac06-898d22b80cfe/67967675457.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d9e3e04d-f80e-4c02-a7af-9a185316aa3c/target_return_policy_no_receipt_baby_registry.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6eb1ef5d-2933-472b-9e13-a4fe7ebbe5db/wewowu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dff98bdf-4525-4414-9b73-981be04b2d5c/26837484627.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b2361128-4ace-4e7a-a0c6-3e6a232b32b4/frp_bypass_apk_2017_download_free_works_100_-_techoxygen.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/3420/6620/files/53661911561.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/69e65256-0326-435e-beff-6856ae856ad7/wenowebi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fe41a766-697c-4c92-8eb0-10b2735890aa/rivezamajo.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0479/1916/9702/files/bobunokik.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/24a378fe-408f-4102-9a77-6412ada12781/40855106584.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a7763f96-b523-4c5f-82d2-be124a57e6fb/87021001316.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007276.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7276 4076 bytes
SHA-256: ee58f6c144c5bbaa733e5fb92e79c3f223627e3a5dae466c21fcf2cad28a8b94
font_01_sfnt_off000080d3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x80D3 4708 bytes
SHA-256: 6aa959fa14af54bdd429124594ecbd5e3152a207689a471a517010e0b1c27c31
font_02_sfnt_off000090ce.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x90CE 10536 bytes
SHA-256: 2906da8a6c6f3392e2a0423541c12cfd6a53c2e770d4bdbe0b358686de36c355
font_03_sfnt_off0000b4f1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB4F1 4324 bytes
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f