Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3a58556f9e4e236…

MALICIOUS

PDF

56.3 KB Created: 2020-10-28 06:33:00 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-05
MD5: de7960a09cf5bdaa46116bf88876c1ef SHA-1: bf7af541c9c1560a8fc3b16d4ef100b76305cc6c SHA-256: e3a58556f9e4e236ccf1bb8948d710490bfea11f363d9d5344b4cfedc6bc75ac
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many pointing to disposable hosting and a known malicious redirector. This indicates a link farm designed to distribute traffic to potentially malicious sites. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/123?keyword=rocky+mountain+brown+club In PDF document text
    • https://cdn-cms.f-static.net/uploads/4366029/normal_5f978c086101c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4403674/normal_5f91163bb552c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391340/normal_5f93d2b2301e1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4414678/normal_5f952313b3453.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365649/normal_5f87535241ce4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374372/normal_5f8e88940f611.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369168/normal_5f8f5f35c3510.pdfIn PDF document text
    • https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/tasezekavudosewulo.pdfIn PDF document text
    • https://xufiwelak.weebly.com/uploads/1/3/1/1/131164558/sekiderib_kexedi.pdfIn PDF document text
    • https://fidevawane.weebly.com/uploads/1/3/0/8/130814252/46e9ec8.pdfIn PDF document text
    • https://wubixuduliku.weebly.com/uploads/1/3/4/4/134466255/satukaruzabajeme.pdfIn PDF document text
    • https://lexizade.weebly.com/uploads/1/3/4/3/134368494/jojezowudaxuv-fonekovon-labadojokil-jibivoduw.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0478/1791/6575/files/97345522290.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0430/8104/0033/files/kuxiteluniziregigikef.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0431/9074/7295/files/gonowapogut.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4642df15-a269-4ece-bfed-fa9c4e2dc376/gate_2008_question_paper_cs_with_sol.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/48768d59-f7dc-4620-b33d-ffc1956f3021/nubilubujoxisebovodem.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6a8d1e1a-cbc4-49d8-96db-b3f5035ceec9/xasosunamaranogufujez.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b2bc4cb9-4f98-4170-97d6-2c8ccf4c6c80/juwujir.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/845962e5-43c3-4360-a89b-c01358b2e83e/neil_gaiman_american_gods_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/88d4d08d-cf14-4a90-9726-f1269ea6730e/40265530756.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009bd7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9BD7 5172 bytes
SHA-256: 1b60c2cc95018a4bb7e8965bd0796a271b5e90ad88d39ffea6bab284b9fc1901
font_01_sfnt_off0000ad73.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAD73 11400 bytes
SHA-256: 79a17e96b4b9c713c8b20ddc5f8ef8b2045a421965349691e89aace1152da395