Malicious PDF — malware analysis report

Static analysis result for SHA-256 c98c4641533a2913…

MALICIOUS

PDF

55.4 KB Created: 2020-10-25 07:23:04 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e0c8ba2f6f47b3abd30b2bc330e73f39 SHA-1: 1a6ff58043abc3e978aface7d29df21952808f3a SHA-256: c98c4641533a29133dd57248c61c7942f2be1442631634a4abba3b8ceccf0f53
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://gettraff.ru/123?keyword=analog+film+full+pack+apk'. It also exhibits characteristics of a link farm, with numerous embedded URLs, many of which are benign PDFs hosted on cloud storage. The ML classifier strongly indicated maliciousness. The document body, though heavily obfuscated, contains the malicious URL and appears to be a lure for an 'apk' download.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/123?keyword=analog+film+full+pack+apk
    • https://suganolorifumu.weebly.com/uploads/1/3/0/8/130814011/3257f1d1a.pdf
    • https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/megumepagusib_nomozosodeb_julibitozutusaf.pdf
    • https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/nunenemajewejawiki.pdf
    • https://putigazabikikim.weebly.com/uploads/1/3/2/6/132682718/99c98c.pdf
    • https://risimukino.weebly.com/uploads/1/3/1/3/131383953/zovunodafad-xugasamoko-doromobegiv-zakuzesive.pdf
    • https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/5ef07c25ec89c5b.pdf
    • https://zalawevovupat.weebly.com/uploads/1/3/0/9/130969727/ab10a366407.pdf
    • https://nimorozidu.weebly.com/uploads/1/3/4/3/134373006/224571.pdf
    • https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/wijije_wisutenot.pdf
    • https://dokakida.weebly.com/uploads/1/3/1/3/131380589/f7c167f.pdf
    • https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/059d55fbff3.pdf
    • https://gudojovevisepu.weebly.com/uploads/1/3/4/3/134314990/188202844c.pdf
    • https://jojawetoterul.weebly.com/uploads/1/3/4/4/134404105/lapitulexobav_zuwejo_vapebutujomab_vosewuzo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/pazifetanegapu/object_relative_clauses_exercises.pdf
    • https://s3.amazonaws.com/zaxawetawupo/vertical_axis_wind_turbine_design_calculations.pdf
    • https://s3.amazonaws.com/jamokaroxoj/48501092612.pdf
    • https://s3.amazonaws.com/bugutaj/rudekobeluvepotusosop.pdf
    • https://cdn.shopify.com/s/files/1/0504/5393/8366/files/canary_islands_resorts_guide.pdf
    • https://cdn.shopify.com/s/files/1/0433/4649/3605/files/bouncer_android_app_review.pdf
    • https://cdn.shopify.com/s/files/1/0497/9461/3410/files/terner_watch_company.pdf
    • https://cdn.shopify.com/s/files/1/0486/1794/7296/files/bagag.pdf
    • https://uploads.strikinglycdn.com/files/337e5e14-eac2-4e0a-8ab4-a39bd3cd5bf8/22084781629.pdf
    • https://uploads.strikinglycdn.com/files/f77bc482-fd5d-4031-a5e7-394991f49d44/41397520593.pdf
    • https://uploads.strikinglycdn.com/files/86b8a08e-92c0-4fa2-8146-fa0c26f934fd/74969697987.pdf
    • https://uploads.strikinglycdn.com/files/7d193a10-94b1-4019-9826-e1492611068b/buworajilivolego.pdf
    • https://uploads.strikinglycdn.com/files/cc2a2149-8b07-4749-b18c-e18d5ff1b291/51454877161.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005caf.bin
4e1a9c4cb32f1bc4ff176ae4dc1460c31b2d267bf2def0252f23ad2731e7be72
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CAF 6588 bytes
font_01_sfnt_off00006cf7.bin
035d5e13fa64f23e341a8fa4b3f8a243489912f9213c0a8030aef57867badb01
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CF7 3084 bytes
font_02_sfnt_off000077fa.bin
3fcf3621d593ff0adbc3fa14a1f904b378be0bcd9c8de27b5143fe7477bbd202
pdf-font-stream PDF embedded font (sfnt) at offset 0x77FA 5116 bytes
font_03_sfnt_off00008955.bin
8243a2978354b99ad9fc1765d3878328d49e2998d0a5549394a0bdfef85e0506
pdf-font-stream PDF embedded font (sfnt) at offset 0x8955 2188 bytes
font_04_sfnt_off00009374.bin
61dce34261b0fa1dd13b93247454b7fbc2d3c725f470c26fdab4397682cce08b
pdf-font-stream PDF embedded font (sfnt) at offset 0x9374 11408 bytes
font_05_sfnt_off0000b9fb.bin
df1d2c903cabdf2976887e260da0b25217edeb5ce2b71f315001024534e8e210
pdf-font-stream PDF embedded font (sfnt) at offset 0xB9FB 16060 bytes