Malicious PDF — malware analysis report

Static analysis result for SHA-256 d2bd452dba3ad060…

MALICIOUS

PDF

71.9 KB Created: 2020-10-27 01:22:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a07088a5d04d54da933da27e1169efac SHA-1: 35434d48b4f56930e9497c2083204761803f45dc SHA-256: d2bd452dba3ad060ce0c2255d9ee6be4c219e6ef677e0770d7ca778373509c93
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with a critical heuristic firing for a malicious redirector. The primary malicious URL identified is 'https://ggtraff.ru/wb?keyword=definisi%20genu%20valgum%20pdf', which is likely used to redirect users to a malicious site. The document body, though heavily obfuscated, also contains this URL, suggesting it's the intended destination. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/wb?keyword=definisi%20genu%20valgum%20pdf
    • https://nizesuvijeva.weebly.com/uploads/1/3/1/6/131607023/vilawedalote.pdf
    • https://sirawomaperuli.weebly.com/uploads/1/3/1/3/131398091/fogikisimixe_wadazemigonu_xitudi.pdf
    • https://gogebuzavoriro.weebly.com/uploads/1/3/2/6/132681212/fubiva-lamemumoj-wezexo.pdf
    • https://sazojowob.weebly.com/uploads/1/3/4/3/134351878/8bf0c8c6f5c369.pdf
    • https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/nukunuraki.pdf
    • https://dipakinujudisil.weebly.com/uploads/1/3/4/4/134468351/7192789.pdf
    • https://duxawedi.weebly.com/uploads/1/3/4/4/134477895/6933930.pdf
    • https://sigakoge.weebly.com/uploads/1/3/4/4/134437147/nomovuw.pdf
    • https://dokodajibebabek.weebly.com/uploads/1/3/2/3/132302773/4235290.pdf
    • https://sexozorojupur.weebly.com/uploads/1/3/4/3/134390270/07741b1.pdf
    • https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/zewosa.pdf
    • https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/fd9fe9.pdf
    • https://samomalekadoj.weebly.com/uploads/1/3/1/4/131438786/nadatu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/33d6187b-67cc-4b09-99ab-db867b0cec9f/34947469793.pdf
    • https://uploads.strikinglycdn.com/files/199553a6-3d88-4a09-8fb6-79e802e7a23c/xabotaminasud.pdf
    • https://uploads.strikinglycdn.com/files/336d5a7c-997e-429e-81b2-567cf3c9eb63/tamidezegudi.pdf
    • https://cdn.shopify.com/s/files/1/0266/8842/2067/files/canned_banana_blossom_near_me.pdf
    • https://s3.amazonaws.com/juzinaramip/6223820900.pdf
    • https://s3.amazonaws.com/susopuzupure/3203948065.pdf
    • https://s3.amazonaws.com/gupuso/gexidezowiwu.pdf
    • https://s3.amazonaws.com/buxoparadazegu/endoscopic_anatomy_of_nose.pdf
    • https://s3.amazonaws.com/bugutaj/theme_in_literature_definition.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d99c.bin
9652d7d1020d93a72abe7c8a8db7135bff2140a01b639c1c5261ae4fe95d801c
pdf-font-stream PDF embedded font (sfnt) at offset 0xD99C 5324 bytes
font_01_sfnt_off0000ebbb.bin
e777a4ed1cea84c349ce67ca0276797f3c808cdf4cdb502c0de4870bff8ae663
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBBB 11344 bytes