Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee3f13a8791d5409…

MALICIOUS

PDF

60.4 KB Created: 2020-08-03 15:56:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f99d5149a1e368642c2a517a0d8014d4 SHA-1: 71faebb027cc31fb857c7e675e6a6e375b85f169 SHA-256: ee3f13a8791d5409cf402b43c56a30f9f5d93286f0b3496ffc260b0d22eca17c
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged as malicious due to a critical heuristic identifying it as a redirector link to known malicious infrastructure. It also contains a large number of external PDF links, characteristic of a link farm. The document body contains the URL that leads to the malicious redirector, suggesting the document's primary purpose is to lure users to this malicious site. No scripts were extracted, and the PDF structure itself is the vector for the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=insomniac+city+bill+hayes+pdf
    • http://files.baln.org/uploads/1/3/1/8/131871414/18182deba1.pdf
    • http://files.mooresmasterminds.com/uploads/1/3/0/8/130813859/tozogilagix.pdf
    • http://files.chsmarketplace.com/uploads/1/3/1/8/131871977/3927535.pdf
    • http://files.gillettehandyman.com/uploads/1/3/1/8/131871980/bd4ade86.pdf
    • https://cdn.shopify.com/s/files/1/0437/8787/8549/files/tomukawipuxesixepegaxo.pdf
    • https://cdn.shopify.com/s/files/1/0435/8651/9208/files/31969401148.pdf
    • https://cdn.shopify.com/s/files/1/0439/4074/1278/files/kisadojuzeke.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/85286147205.pdf
    • https://cdn.shopify.com/s/files/1/0427/7967/2735/files/89673780583.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/bixebor.pdf
    • https://cdn.shopify.com/s/files/1/0431/4100/5480/files/rulosi.pdf
    • https://cdn.shopify.com/s/files/1/0432/7066/8453/files/85395141981.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/kosetomamevisired.pdf
    • https://cdn.shopify.com/s/files/1/0434/3991/5164/files/vegevelufebuxatem.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009da6.bin
31fc2c2f2bc84c8fbc9eda736ac855c48c12f42d0fd53745521b437d1f34e8cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x9DA6 4740 bytes
font_01_sfnt_off0000ae24.bin
8e169e4a8854e9e5692888905a7072c096771364b7f8861a450200e85b028fab
pdf-font-stream PDF embedded font (sfnt) at offset 0xAE24 5476 bytes
font_02_sfnt_off0000c09d.bin
cb4d0137dfe634aef38a5f81b8ef70f334888a3c174949dccef619c131abd23e
pdf-font-stream PDF embedded font (sfnt) at offset 0xC09D 10632 bytes