Malicious PDF — malware analysis report

Static analysis result for SHA-256 f71e1f5e6e6ed333…

MALICIOUS

PDF

39.2 KB Created: 2020-08-07 10:17:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9b0b0b0f61d1a0842ac591ca02d3745a SHA-1: 8a5862cbb801964d64d087435e46f4753bcab6c0 SHA-256: f71e1f5e6e6ed3332a0f6bdb9a122a7b96cf446fe966b6f126a4f95908b9538c
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged as malicious due to a high number of embedded links, many of which lead to a redirector service. This suggests a link farm or redirection attack designed to obscure the ultimate destination of the malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the content's intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=guia+holman+de+apologetica+cristiana+pdf
    • http://niwatudu.charlaphysed.com/uploads/1/3/0/9/130969426/2866157.pdf
    • http://kowob.holsteinstatetheatre.com/uploads/1/3/2/6/132681579/kajasavara.pdf
    • http://files.amaniabraham.com/uploads/1/3/2/8/132814097/2525609.pdf
    • http://files.nhswomenslacrosse.com/uploads/1/3/1/4/131438418/9473772.pdf
    • http://tixod.rkeenelaw.com/uploads/1/3/1/8/131858685/tiroxodo.pdf
    • https://cdn.shopify.com/s/files/1/0438/4551/7469/files/kidosotixigod.pdf
    • https://cdn.shopify.com/s/files/1/0429/7618/2426/files/850940219.pdf
    • https://cdn.shopify.com/s/files/1/0437/6972/5085/files/xumekedakopamemofeguf.pdf
    • https://cdn.shopify.com/s/files/1/0433/8414/4037/files/59281191592.pdf
    • https://cdn.shopify.com/s/files/1/0434/2690/6264/files/56481365069.pdf
    • https://cdn.shopify.com/s/files/1/0428/3708/2271/files/68341610059.pdf
    • https://cdn.shopify.com/s/files/1/0433/1087/4777/files/65332659860.pdf
    • https://cdn.shopify.com/s/files/1/0432/1925/5454/files/kojubedexuperopozaxen.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/20880330559.pdf
    • https://cdn.shopify.com/s/files/1/0438/7074/8827/files/24547445711.pdf
    • https://cdn.shopify.com/s/files/1/0430/8716/7641/files/71340131901.pdf
    • https://cdn.shopify.com/s/files/1/0429/8558/6849/files/8765371358.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/93236297381.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000596a.bin
9703c864a68b18e955f6d99f694214e58194ca01b63f5ceac1d5534061ca8bb8
pdf-font-stream PDF embedded font (sfnt) at offset 0x596A 5600 bytes
font_01_sfnt_off00006c4e.bin
8503bf8690131bfff1704e6b7946d27edffacbdd2958450887b5f7f2635b09aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C4E 10288 bytes