Malicious PDF — malware analysis report

Static analysis result for SHA-256 f8f5867d65dbe76b…

MALICIOUS

PDF

57.9 KB Created: 2020-10-27 02:34:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-26
MD5: 991ffda91bb8d10dc49b5fefa44b1d84 SHA-1: 169015bad18fe6eca3e786d9b0ed45b12ca708ca SHA-256: f8f5867d65dbe76b9aa6c1b7225111a56e0b0ba4f82fdbf85cd8c9b8b7bb9f2d
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous links, including one identified as a malicious redirector, which is likely intended to lead the user to a malicious site. The document body, though heavily obfuscated, contains text related to downloading an APK and the malicious URL itself, suggesting a lure for users seeking software. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=cartoon+hd+apk+download+for+android+latest+version In PDF document text
    • https://cdn-cms.f-static.net/uploads/4375196/normal_5f8d0b4f0cb16.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4384164/normal_5f9103cbd2290.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374533/normal_5f891286e2d55.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0502/3508/0879/files/mp_higher_education_syllabus_2020.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0481/5100/3303/files/tisululasejesakaxigutep.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0498/1017/8211/files/mp3_player_app_apk_download.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/7180/6366/files/hungry_shark_evolution_apk_mod_latest_version.pdfIn PDF document text
    • https://s3.amazonaws.com/lopadivupudexa/89000431662.pdfIn PDF document text
    • https://s3.amazonaws.com/wonoti/personality_development_quiz.pdfIn PDF document text
    • https://s3.amazonaws.com/nawuvud/bonolota_sen_free_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/42e1405a-18b7-4ff6-a4f9-77eb7125c847/civpro_outline_nyu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ccd7e843-9763-4ec5-84ec-83b0cd23ea1a/8213297259.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0502/9344/0697/files/77879127752.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0484/3120/2458/files/zesogiresinupana.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eeaf5497-e26d-4845-a150-e63268404596/41686504018.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3d447ed9-2ee2-4ab1-9ead-80870c6c4e19/75630598089.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/30a46135-44ed-4b21-8590-66643d956d72/keleve.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7af2c68f-e799-4217-9a18-d8b34e166aa8/18752698503.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a2cd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA2CD 5252 bytes
SHA-256: d60e67c15644846bb5ce00a7ce2a1c14cf58e3288687aaecaa18f965569bd9e5
font_01_sfnt_off0000b4ba.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB4BA 11016 bytes
SHA-256: 5bcfde3cef3ebfeb0eb61590fc9390fd4386372131748049162865c06d132f63