Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee899e3f3aff64b1…

MALICIOUS

PDF

54.6 KB Created: 2020-10-18 14:39:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2020-12-28
MD5: b57190e251fd93c53eb1bc967d9dc883 SHA-1: 007278cf787ebab95b4cda9058e1e617945eddae SHA-256: ee899e3f3aff64b1db62fa347e2b81bc28defb4aa542e7dca5c87d53e217af2c
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, with one identified as a malicious redirector. The ML classifier also strongly indicated maliciousness. This suggests the document is designed to lead users to malicious sites, potentially for phishing or to host further malware. No scripts were extracted, but the presence of a malicious redirector is a high-confidence indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/123?keyword=manualidades+navide%25C3%25B1as+para+ni%25C3%25B1os+con+limpiapipas In PDF document text
    • https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/9e8409928.pdfIn PDF document text
    • https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/dekefomivupe-kovak-talajonipa-fedebiraroz.pdfIn PDF document text
    • https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/f4d4264b47f445d.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/2429a69a-acc8-4536-aad4-6f3d682d29f7/jowigifevuzolowusawifu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1eb76c3a-aa71-46b6-8ad8-672e55a2097a/67218854524.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/63f94bec-6217-4ce0-acbb-884c2818b388/bejewaxifirelefumiverorep.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8a4cb1f6-7417-4da7-b477-e89caac3a295/48751188024.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c380cf6f-2901-48aa-a5fa-93113b987450/pavefosobud.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0495/6507/3560/files/kowutezidatod.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0497/8494/6850/files/historia_de_la_literatura_universal_libro.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/9709/5333/files/pexuzemenuwepexomaxemofe.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0428/9455/7350/files/dazigugemoboxumoxogafo.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0266/8540/7421/files/ff14_gtterdmmerung_leviathan_guide.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/5664/3739/files/86737549895.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0438/4397/7366/files/mario_and_the_magician_film.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/5089/2454/files/t_l_ko_nh_ci.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0503/1834/4350/files/libro_ortografia_de_la_lengua_espaola.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000067be.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x67BE 5300 bytes
SHA-256: 6a671515c3cc8e88eca34f949d6b6189f75bfe5bcd949817ecca1055edad414d
font_01_sfnt_off00007952.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7952 1800 bytes
SHA-256: a36eee06fef6ce219692c4ec918276ac99413e4fd1e3666e4031624f9289d620
font_02_sfnt_off000081df.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x81DF 11360 bytes
SHA-256: 749bd3378c471b157dabf9929366987a42d811e220a987c153b566decc7b4110
font_03_sfnt_off0000a610.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA610 16376 bytes
SHA-256: 069f5cdcb972b33999f3dc18a3e5b847fc2aa024b7c5b45b4734cedf253a8e5c
font_04_sfnt_off0000bbb7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBBB7 4324 bytes
SHA-256: 0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333