Malicious PDF — malware analysis report

Static analysis result for SHA-256 beec814647991173…

MALICIOUS

PDF

81.3 KB Created: 2020-10-31 23:06:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: 46778bc8577895935a11f07313ee1c55 SHA-1: daf11b246d8765fc79cd90699ee9ba504756656d SHA-256: beec81464799117365d3dc1d47569b83083fe105482d074177d4fdf0c4d44d35
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by an ML classifier. It uses a password-protected-archive lure. The file embeds a large number of external links characteristic of an SEO link farm and routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/123?keyword=android+pie+apk+launcher In PDF document text
    • https://cdn-cms.f-static.net/uploads/4368731/normal_5f885490cce80.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4372373/normal_5f8ad4eba5237.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366336/normal_5f94ddeb9f4b0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365575/normal_5f8709d80c8f2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368488/normal_5f8de14b0d3e3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366034/normal_5f87e90acdd55.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0501/2881/4273/files/information_technology_law_6th_edition.pdfIn PDF document text
    • https://s3.amazonaws.com/tonemakopinibem/rat_race_games.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/3254/2369/files/pafexebikewafifi.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0507/1654/1124/files/1000_cca_battery_for_sale.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0428/2161/5783/files/snare_drum_exercises_sheet_music.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0500/0360/7702/files/avent_manual_pump_instructions.pdfIn PDF document text
    • https://s3.amazonaws.com/zikeko/86249418029.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0501/3510/5724/files/remote_method_invocation_in_java.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5e2ca435-c9eb-4c59-bd5f-498cfd4b07aa/zewazefexevi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cbc0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCBC0 2972 bytes
SHA-256: 99db71a5482ce5dc44376ac6cb5f07ebbc5d66d64a2a6ba9b30384185a29d6e1
font_01_sfnt_off0000d65d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD65D 5036 bytes
SHA-256: e816ba1a6f58b4b99e3a1f8f9e440c02851ee5ab9854eb096043dbe700b7e078
font_02_sfnt_off0000e773.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE773 2532 bytes
SHA-256: 2ed01a800431d81856155c0908aeaa745912f39882557d1def1cfc6c9b7abd0a
font_03_sfnt_off0000f29a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF29A 12052 bytes
SHA-256: 8a9621c3908b34c2f9d8f6ec2569db6e9a028fba84bb2e5fabf0992b0b0cdde0
font_04_sfnt_off00011baf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11BAF 17480 bytes
SHA-256: 874655bd4e1b81b2323772bcac58c1c76fa3156773a1494cc785ebe90fdd4e02