Malicious PDF — malware analysis report

Static analysis result for SHA-256 c24696db3d082237…

MALICIOUS

PDF

47.3 KB Created: 2020-08-19 14:18:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3a0154f6344a864b1327dc5cc866312b SHA-1: 3816efaf1709b0c1517398e7d10aa1941538e75c SHA-256: c24696db3d0822378e227de1913d98ea8625530ba18818e44a0da57d33eda42a
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm pointing to numerous external PDFs, with one primary link leading to a known malicious redirector. The document body, though heavily obfuscated, contains the same URL as the primary malicious link, suggesting the document's intent is to drive traffic to this redirector. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=leveling+guide+destiny+2+forsaken
    • http://pesir.thebluebbla.com/uploads/1/3/2/6/132682646/2a32b5754fde90.pdf
    • http://files.communityfarmersmarketbg.com/uploads/1/3/1/0/131070872/setiwezukusuz-puderojogibado.pdf
    • http://zosabefi.aledobandboosters.org/uploads/1/3/1/4/131438641/dumosemefoxip.pdf
    • http://files.sacredstarastrology.com/uploads/1/3/1/4/131483031/wigamofixiju.pdf
    • https://cdn.shopify.com/s/files/1/0440/1584/5541/files/clause_49_of_listing_agreement.pdf
    • https://cdn.shopify.com/s/files/1/0429/4931/2666/files/sowowupoxuluzufob.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/96056065099.pdf
    • https://cdn.shopify.com/s/files/1/0436/0326/3650/files/mossberg_500_for_sale_walmart.pdf
    • https://cdn.shopify.com/s/files/1/0432/2436/7262/files/65923925102.pdf
    • https://cdn.shopify.com/s/files/1/0428/7689/5398/files/divetivudemufowifaf.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/21511039237.pdf
    • https://cdn.shopify.com/s/files/1/0439/5224/2856/files/54541767211.pdf
    • https://cdn.shopify.com/s/files/1/0430/8451/3440/files/kifuwonewudalaz.pdf
    • https://cdn.shopify.com/s/files/1/0428/6709/7756/files/mepefanamizu.pdf
    • https://cdn.shopify.com/s/files/1/0432/9072/2469/files/80641747059.pdf
    • https://cdn.shopify.com/s/files/1/0434/2310/5189/files/5918926177.pdf
    • https://cdn.shopify.com/s/files/1/0446/7798/8505/files/bible_story_book.pdf
    • https://cdn.shopify.com/s/files/1/0435/9602/1919/files/digital_marketing_agency_company_profile.pdf
    • https://cdn.shopify.com/s/files/1/0429/2768/5788/files/pufosidofa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007bc6.bin
249d4097371775cbcd982b8f9ee18fda3a71c5cc51538aa8e012f52af5ac4bdc
pdf-font-stream PDF embedded font (sfnt) at offset 0x7BC6 5372 bytes
font_01_sfnt_off00008e3a.bin
b26b7b7481207eeb4b8356744be4c5af380a93f2689a4a95f5889c741e742549
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E3A 10048 bytes