Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd501fb6eba12a8f…

MALICIOUS

PDF

57.5 KB Created: 2020-10-26 05:00:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: 81de7ab877fb2b3bf53127b3eabd3ee3 SHA-1: 8aab8134a5e6ddfcbafc94807fb319ccd1931c32 SHA-256: fd501fb6eba12a8fe1f6a3e0c68498ea761233acc8dc2dfbab9eff7dca0faef3
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a significant number of embedded links, with one pointing to a known malicious redirector. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external PDF links, suggesting an attempt to manipulate search engine results or distribute further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/123?keyword=android+table+row+center+programmatically In PDF document text
    • https://cdn-cms.f-static.net/uploads/4378157/normal_5f8b6fea6442e.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/f3ec58e9-eca3-4240-ad0f-3cc7d14a934c/libro_de_juan_garcia_colin_contabilidad_de_costos.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e7ce0218-5457-404d-8d1b-f4104b6bf92e/24057792245.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a459ab26-4ce0-42b4-8dd6-5b1817bdc86e/nugejuberafazeponolizuwo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cf2e43ee-fe52-46de-93f3-1e03b103819f/rafibofe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/971c4bc2-aaa0-48fb-8dc9-808740a8e9b6/dark_cloud_strategy_guide.pdfIn PDF document text
    • https://s3.amazonaws.com/henghuili-files2/kowogebekukixa.pdfIn PDF document text
    • https://s3.amazonaws.com/sukobogixe/lezawukadox.pdfIn PDF document text
    • https://s3.amazonaws.com/jaxesabi/23428788995.pdfIn PDF document text
    • https://s3.amazonaws.com/jewizopukuni/ap_10th_class_maths_textbook_english_medium.pdfIn PDF document text
    • https://s3.amazonaws.com/zuxadol/hanuman_chalisa_image.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0496/5295/7335/files/92369028140.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0499/5822/4040/files/24099144338.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0502/5801/8472/files/the_procedure_handbook_of_arc_welding_13th_edition.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0485/1181/1739/files/benunevegaja.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/6510/6847/files/big_word_whizzle_answers.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/4161/9100/files/53570231345.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0483/9689/4357/files/zefobelatozirigafanen.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0498/0034/7810/files/lmu_library_phone_number.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0498/7502/6078/files/android_expand_layout_animation.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5eabeea8-28b1-4a40-8d2d-8df9d7e6d527/vidivodo_video_indirme.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/62578dcd-cc1f-41f7-b771-f5c4e4193e84/cocoa_programming_for_mac_os_x_5th_e.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4a236c79-bb59-4568-baec-e501b368d532/modanurivekuvufamawujok.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007b9c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7B9C 6096 bytes
SHA-256: f2ae8db9c9172920111f0ec93736d23f60590b54a0b1668295bc0d7803723a0b
font_01_sfnt_off0000903a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x903A 5324 bytes
SHA-256: 820964f42ec15b8afd84b9eeae719d4fa4770681cfbfba42ee97865a244a59c8
font_02_sfnt_off0000a249.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA249 11620 bytes
SHA-256: 522f669cc3f88c39202c2aa4aa4a237174c9c771f277a947a8aa19402b17aad4
font_03_sfnt_off0000c9dd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC9DD 4324 bytes
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f