Malicious PDF — malware analysis report

Static analysis result for SHA-256 b817af2b72a08031…

MALICIOUS

PDF

85.6 KB Created: 2020-11-03 20:53:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1f5810cdd8c5c4d4b95041abe5417d27 SHA-1: 3cf9617383f82fac5b9249a00543333e12073cdb SHA-256: b817af2b72a080316f63325b756de7cbf5b2d6e579da76d062aff8611842dd66
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to link farms and redirectors, indicating a malicious intent to direct users to potentially harmful sites. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' specifically flags a URL leading to known malicious infrastructure. While no scripts were extracted, the structure and embedded links strongly suggest a phishing or redirection attack, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/aws?keyword=naruto+kisses+ino+fanfic
    • https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/6498151.pdf
    • https://xepebujusu.weebly.com/uploads/1/3/4/3/134319702/buretakigozaro.pdf
    • https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/2613559.pdf
    • https://kavaxaxogemiren.weebly.com/uploads/1/3/4/4/134441995/1000158.pdf
    • https://melegejisud.weebly.com/uploads/1/3/1/3/131379421/jelonojemoz.pdf
    • https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/3718456.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/jezaxojipevu/google_web_search_homepage_download.pdf
    • https://s3.amazonaws.com/subud/faringoamigdalitis_bacteriana.pdf
    • https://s3.amazonaws.com/biwubeleba/how_to_clean_thermal_paste_off_ps4.pdf
    • https://uploads.strikinglycdn.com/files/e2aca328-88f2-4faa-991e-99e0ea3c78fd/fapajaraxerapos.pdf
    • https://s3.amazonaws.com/xesigeze/vatekiru.pdf
    • https://s3.amazonaws.com/pisedij/magruders_american_government_workbook_answers.pdf
    • https://s3.amazonaws.com/vatosolikijike/0-100_chart.pdf
    • https://uploads.strikinglycdn.com/files/ebe0a01c-f95e-4c16-b6c7-9f95ea9cea60/36302034715.pdf
    • https://uploads.strikinglycdn.com/files/9402b68f-75bc-4b66-b004-c6803f0f077c/fegewu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fc18.bin
f92965ae67af79eb5c2a2987f687396e025d91a13f8b7512a762b958181d534a
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC18 4876 bytes
font_01_sfnt_off00010cc9.bin
30b550238d3afd8e1d9959db9425e34006736a8073c906b24dda6aa8bc87ece8
pdf-font-stream PDF embedded font (sfnt) at offset 0x10CC9 10292 bytes
font_02_sfnt_off00012f5f.bin
68e879c2c87bdf0855db0641fe96b06e5b8be242b8ec1103446954577df962fd
pdf-font-stream PDF embedded font (sfnt) at offset 0x12F5F 17384 bytes