Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca565b3ef136a977…

MALICIOUS

PDF

68.3 KB Created: 2020-10-28 15:13:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ae9ad1a4532785ceaa7b13ffb54b8bbd SHA-1: 72941cc342505fc33cf159ff1df0663894557ca4 SHA-256: ca565b3ef136a977b7be28f66e20aac54abd6794f66f007a31ddc2b49e50affb
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, one of which points to a known malicious redirector infrastructure. The document body, though heavily obfuscated, appears to contain keywords related to popular games, likely as a lure. The presence of multiple embedded PDF links suggests an attempt to create a link farm or distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/123?keyword=pokemon+yellow+mew+glitch+lavender+town
    • https://towetebofipu.weebly.com/uploads/1/3/1/4/131437669/0a325a.pdf
    • https://vuguzakinizole.weebly.com/uploads/1/3/4/4/134493236/769e024dc.pdf
    • https://baletepo.weebly.com/uploads/1/3/0/7/130776023/jebab.pdf
    • https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/7904132.pdf
    • https://vemifibu.weebly.com/uploads/1/3/4/3/134354414/wowarexoxige.pdf
    • https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/15e8d3c62b9a40e.pdf
    • https://bubixoduxufito.weebly.com/uploads/1/3/1/0/131070588/2d5335c4874eff.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0504/8998/3136/files/leisure_time_activities_worksheets.pdf
    • https://uploads.strikinglycdn.com/files/9a05e328-268d-4dc2-b583-e306186ff908/95017218133.pdf
    • https://uploads.strikinglycdn.com/files/2257ce2c-19f3-4e54-9fdf-c3723ed558a6/morevoj.pdf
    • https://uploads.strikinglycdn.com/files/cfc30d77-c973-4be8-9feb-88cb065653ac/25848043852.pdf
    • https://uploads.strikinglycdn.com/files/a6e40c5c-e8c7-4594-8c39-77809d7f7af9/73673379775.pdf
    • https://uploads.strikinglycdn.com/files/dee5bdab-d5e5-4846-a136-afb5f7abdca4/zolumanibipisetivifi.pdf
    • https://uploads.strikinglycdn.com/files/b042e445-da45-4d00-996f-cebef0e5fcd1/vegavikurowerulif.pdf
    • https://uploads.strikinglycdn.com/files/b45f15df-0a3f-4643-8bed-c33ac488a664/kordil_edms_tutorial.pdf
    • https://uploads.strikinglycdn.com/files/713d59ab-4be9-407b-bc67-d9a245cae8b9/76778723096.pdf
    • https://cdn.shopify.com/s/files/1/0492/2484/3420/files/gavuzifugamoxov.pdf
    • https://cdn.shopify.com/s/files/1/0438/8775/5432/files/spirit_bond_ffxiv.pdf
    • https://uploads.strikinglycdn.com/files/1bb9cb6f-d1cb-44c6-8f9b-042b83c653bf/23243551296.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a238.bin
153cb78d4a1fa6da874a669a512ae8b7fda45871ae40ea86962ab7137767f04a
pdf-font-stream PDF embedded font (sfnt) at offset 0xA238 5132 bytes
font_01_sfnt_off0000b43b.bin
b213910cb61bd6b5ee22b313b4fea4dda19983c2d1b7fa798b73c621b1abc477
pdf-font-stream PDF embedded font (sfnt) at offset 0xB43B 5496 bytes
font_02_sfnt_off0000c6e9.bin
05717e664b4d3cd3d381fa25f19cb4cef7251504cc9455ba02aff0ef818c9e90
pdf-font-stream PDF embedded font (sfnt) at offset 0xC6E9 11052 bytes
font_03_sfnt_off0000ec54.bin
12bdfdd26b42687ed6d6e4673084773943fc64d80ea302008a05158b1f99f3df
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC54 16068 bytes