Malicious PDF — malware analysis report

Static analysis result for SHA-256 c67cf98765e02fae…

MALICIOUS

PDF

52.6 KB Created: 2020-10-31 03:37:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fa423e56aa06ce37022e0dc981a62b4e SHA-1: 57275e817b7b63301c9b39c38575a1f64ef18987 SHA-256: c67cf98765e02faed0efa2da7a3e8dba25fba39b058970810d9fb0f8f33e90a8
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a high number of embedded links, many of which point to a known malicious redirector. The ML classifier also flagged this PDF as malicious. The presence of a URL within the document body, specifically 'https://gettraff.ru/aws?keyword=metamorphosis+of+narcissus', strongly suggests an attempt to direct the user to malicious infrastructure. While no scripts were explicitly extracted, the PDF structure and link farm indicate a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/aws?keyword=metamorphosis+of+narcissus
    • https://cdn-cms.f-static.net/uploads/4365599/normal_5f9158ccebf03.pdf
    • https://cdn-cms.f-static.net/uploads/4374703/normal_5f894bb092f71.pdf
    • https://buvitefano.weebly.com/uploads/1/3/4/1/134131500/1380a885e8f.pdf
    • https://cdn-cms.f-static.net/uploads/4369915/normal_5f8b455e51620.pdf
    • https://cdn-cms.f-static.net/uploads/4372399/normal_5f9ca9bb7d427.pdf
    • https://cdn-cms.f-static.net/uploads/4368964/normal_5f88537b5f343.pdf
    • https://cdn-cms.f-static.net/uploads/4366362/normal_5f9a5b364bce2.pdf
    • https://cdn-cms.f-static.net/uploads/4370767/normal_5f91aa9b75751.pdf
    • https://nabisipiguges.weebly.com/uploads/1/3/4/4/134432296/sizugefumu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/53aaa3f0-6684-4f20-8b58-0247d4db2bcf/xejigojito.pdf
    • https://s3.amazonaws.com/pazifetanegapu/ncert_maths_textbook_for_class_12.pdf
    • https://s3.amazonaws.com/jamokaroxoj/benzimidazole_derivatives.pdf
    • https://cdn.shopify.com/s/files/1/0430/3162/5882/files/tk-7_solar_water_heater_controller_manual.pdf
    • https://uploads.strikinglycdn.com/files/0ea97ab2-3ecc-4631-8a98-5f29925b60f0/simumokepagepozisaliv.pdf
    • https://s3.amazonaws.com/kudowo/buzejizepemevewidigatiw.pdf
    • https://s3.amazonaws.com/pusumowi/mason_district_park_trail.pdf
    • https://s3.amazonaws.com/tesotiwapax/besame_mucho_guitar_sheet_music.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008ee2.bin
0345b7b0fbf1d26f40d077f3bb9c537ffb4d2945dc45e1708bc78ffa6d8d0127
pdf-font-stream PDF embedded font (sfnt) at offset 0x8EE2 5108 bytes
font_01_sfnt_off0000a01c.bin
387d275ba1e1939a12305eedecbc4c7af9de22a64462be6dfaf0e4dc1a0d19b8
pdf-font-stream PDF embedded font (sfnt) at offset 0xA01C 11756 bytes
font_02_sfnt_off0000c777.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0xC777 4324 bytes