Malicious PDF — malware analysis report

Static analysis result for SHA-256 e91c2e157d8f8d42…

MALICIOUS

PDF

43.5 KB Created: 2020-10-26 10:14:04 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ec2ca3908956c71b9df952eab3661a60 SHA-1: bf1632e4c6789b08d547d6d8ff05b5316a9520c0 SHA-256: e91c2e157d8f8d422a5c2dc01abfc44a8934b4cd5f4b250df7e5bdbbe37e3fd1
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links that point to known malicious redirector infrastructure, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The ML classifier also flagged the document with high confidence. The document body, though heavily obfuscated, contains URLs that are likely part of a phishing or malware distribution chain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/aws?keyword=flowers+name+in+english+pdf
    • https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kojurufilufopimob.pdf
    • https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/ziwajixukone.pdf
    • https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/e27909d0be.pdf
    • https://cdn-cms.f-static.net/uploads/4370989/normal_5f89698b65888.pdf
    • https://cdn-cms.f-static.net/uploads/4378167/normal_5f91524ecfee3.pdf
    • https://cdn-cms.f-static.net/uploads/4389604/normal_5f8eb1d80db70.pdf
    • https://cdn-cms.f-static.net/uploads/4369182/normal_5f87a2b64212e.pdf
    • https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/roriturosiw.pdf
    • https://zafojepomekosax.weebly.com/uploads/1/3/4/3/134352399/tevumij-nejameroki-vosugun.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/bcfa454b-79d8-40fe-9a7e-b2ec6c8861ff/vatuvekoraseme.pdf
    • https://uploads.strikinglycdn.com/files/46201198-9ffd-4f3c-b9ff-54823746b518/gujatagosigobovoxekojaba.pdf
    • https://uploads.strikinglycdn.com/files/faef8bd9-b3fd-49cb-998d-6b424b3edaba/hotel_front_office_training_manual_w.pdf
    • https://s3.amazonaws.com/bisute/nezezukinopomekubu.pdf
    • https://s3.amazonaws.com/roware/alopecia_por_traccion.pdf
    • https://s3.amazonaws.com/memul/71274303360.pdf
    • https://s3.amazonaws.com/lovetijif/global_warming_and_acid_rain_in_hindi.pdf
    • https://s3.amazonaws.com/bejideba/72081153867.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009961.bin
4ccd599d495500ff9d4210275cf7d8bfd58ad7a601a738845347f56a08689eab
pdf-font-stream PDF embedded font (sfnt) at offset 0x9961 5500 bytes