Malicious PDF — malware analysis report

Static analysis result for SHA-256 ecc5aa251dddcaea…

MALICIOUS

PDF

43.0 KB Created: 2020-10-23 02:43:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: 1316c518f2a3b43da78397e638dc0764 SHA-1: 3e09e6233feecbad9dd3590e8f2733ce8166f6fb SHA-256: ecc5aa251dddcaea2285a2fa6a1abdc9abb924d3cdf544eafbb83a141361e2ef
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, many of which point to a known malicious redirector. The document body, though heavily obfuscated, contains a URL that matches the malicious redirector. This suggests the document is designed to lead users to malicious infrastructure, likely for further exploitation or phishing. The presence of a password archive lure heuristic indicates a common tactic to bypass gateway security.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?keyword=contabilidad+de+costos+1+cristobal+d In PDF document text
    • https://cdn-cms.f-static.net/uploads/4368972/normal_5f8dc45c55287.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366628/normal_5f8d5f9ddf795.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/6c5365c5-a335-4218-a22b-280db1784b95/80350981754.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5644e4bb-2277-41fe-a05c-4669218d546e/85033498241.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/61561478-7432-4957-a760-c6775b83f28e/machete_ao_machote_que_significa.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/0243/6512/files/cstephenmurray_answer_key_physics_color.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0493/3553/3727/files/62177680607.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/5697/1432/files/67054607271.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0497/7036/5095/files/gastec_detector_tube_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8d03451f-f83c-4ad4-9f5d-abc829774e58/39201120645.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c3d1773b-9da4-47cd-afda-85d94b210296/300600559.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ac628617-ca36-4588-965b-744dd0361216/51104538737.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2e1dc52f-14ad-4b8a-ab0b-1acad1510d49/dapom.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4fe00892-5a7b-4913-81cd-afd85818e1b7/vipanexuxuxetenojomuru.pdfIn PDF document text
    • https://s3.amazonaws.com/levovod/dukakitajiguxutelanasuput.pdfIn PDF document text
    • https://s3.amazonaws.com/kewakuko/descriptive_english_grammar.pdfIn PDF document text
    • https://s3.amazonaws.com/fasanag/27657177082.pdfIn PDF document text
    • https://s3.amazonaws.com/jamokaroxoj/53748285267.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d3b87b1a-b3b8-4f33-be93-ca103d69bfd0/28320420637.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f153a6c4-53df-4e20-804c-af366d85c140/92983779365.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9f6b0f9f-420c-434b-a288-ab9e648c39bd/57417669503.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/677f4147-b567-44b5-abaa-ab6b02a54651/76028370736.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3a09e985-6881-4ed7-9ca3-ff4cfb9a2df6/nubutejixumebefevorum.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000585d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x585D 4936 bytes
SHA-256: a62b605f9e5ac4dce9102b1d72f57782db5257b430fda9ab51e92127491c2611
font_01_sfnt_off0000692a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x692A 12084 bytes
SHA-256: b4f1558bf525d2b2df3510d6015078a3b004d0c714ea77c2346b0f09984f0c30
font_02_sfnt_off00008ec7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8EC7 4324 bytes
SHA-256: 1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e