Malicious PDF — malware analysis report

Static analysis result for SHA-256 fad878ccc5ab690b…

MALICIOUS

PDF

52.4 KB Created: 2020-10-26 14:10:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bb005354db022aa004bfe0c374001513 SHA-1: 933b291721874fbe589471295c8eb4e050ca5f91 SHA-256: fad878ccc5ab690bbc6b7af98fe750653b5441c6cce64f8504048fdde4252278
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for linking to a malicious redirector, which is also present in the document body. The PDF also contains a large number of external links, suggesting a link farm or SEO poisoning attempt. The ML classifier strongly indicates maliciousness. The embedded URL is the primary indicator of malicious intent, likely leading to a phishing or malware download site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/123?keyword=block+all+restricted+calls+android
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fejatepudopito/62670747559.pdf
    • https://s3.amazonaws.com/wonoti/eduardo_galeano_el_libro_de_los_abrazos_gratis.pdf
    • https://s3.amazonaws.com/xanebavifamopez/kizosexov.pdf
    • https://s3.amazonaws.com/tesodagiwor/filotisoladubulobiba.pdf
    • https://s3.amazonaws.com/rowubunak/meluremuvazetexumiro.pdf
    • https://s3.amazonaws.com/memul/mewukefokepusogi.pdf
    • https://s3.amazonaws.com/magapeguwabe/64952105701.pdf
    • https://s3.amazonaws.com/sugaguxagu/20863842535.pdf
    • https://s3.amazonaws.com/bisegilupuf/jeevan_umang_brochure.pdf
    • https://cdn.shopify.com/s/files/1/0431/9241/8468/files/55699262345.pdf
    • https://cdn.shopify.com/s/files/1/0266/7787/0786/files/201_knockout_answers_to_tough_interview_questions.pdf
    • https://s3.amazonaws.com/pazifetanegapu/gasukatovezolowizapipav.pdf
    • https://s3.amazonaws.com/dobesogum/kixajilifamuwijuze.pdf
    • https://s3.amazonaws.com/subud/35599353420.pdf
    • https://s3.amazonaws.com/juvetaso/jekitogegogurivuba.pdf
    • https://s3.amazonaws.com/vavebufevodutob/padunodo.pdf
    • https://uploads.strikinglycdn.com/files/0a68e5a9-1747-442e-9aec-c41f7e1c77f0/the_graveyard_book_summary.pdf
    • https://uploads.strikinglycdn.com/files/326ab23c-a383-4475-afa0-9799b588c871/blue_dragon_guide_heroes_guild.pdf
    • https://uploads.strikinglycdn.com/files/2d7858aa-98bf-466a-a97d-258507b32ea2/30072605601.pdf
    • https://uploads.strikinglycdn.com/files/81d5345f-be4f-4886-8c1a-0c9ff7f69d82/5172338083.pdf
    • https://uploads.strikinglycdn.com/files/0a1e4bc0-f1ce-42a1-a917-bb4773b2608d/sinozabemozizitibonimu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008124.bin
58040034d9a45eb7810115ed172137aa9faa5085280ca3a3fc2fae4323186e5b
pdf-font-stream PDF embedded font (sfnt) at offset 0x8124 2996 bytes
font_01_sfnt_off00008be2.bin
06953db4546504fe6e19c22b5b9a9aa9c46dd2940f9af9d7458d9d36f914b358
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BE2 5044 bytes
font_02_sfnt_off00009d0c.bin
dc4aac0b7fbf2e3119a0893097beb62a5bb8f80316d26155635af430a78cbd40
pdf-font-stream PDF embedded font (sfnt) at offset 0x9D0C 11412 bytes