Malicious PDF — malware analysis report

Static analysis result for SHA-256 0265fcd8a640f305…

MALICIOUS

PDF

62.5 KB Created: 2020-08-24 20:18:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c375577d290e86591edb7b90ff9ccc14 SHA-1: 600e4b7043dd447870cb42eda7318913bd80060e SHA-256: 0265fcd8a640f305a80e6ab02c56da66f534f72de7dfe2dd99213cbf6175396f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, with one pointing to a known malicious redirector infrastructure. The document body, though heavily obfuscated, contains text related to 'financial reporting environment ppt' and a URL that appears to be part of a link farm designed to manipulate search engine results. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=financial+reporting+environment+ppt
    • http://files.interwestelectricalsales.com/uploads/1/3/0/7/130775629/8860503.pdf
    • http://files.mikevapes.com/uploads/1/3/1/4/131454034/5e02b43af0b9bc.pdf
    • http://files.travelbycamera.com/uploads/1/3/2/6/132681767/xunizajanij-zijavekinekad-xakomifake.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0438/0003/5485/files/57941682209.pdf
    • https://cdn.shopify.com/s/files/1/0429/6779/3817/files/2990631502.pdf
    • https://cdn.shopify.com/s/files/1/0428/1883/0492/files/3905084342.pdf
    • https://cdn.shopify.com/s/files/1/0433/2562/0374/files/89150993477.pdf
    • https://cdn.shopify.com/s/files/1/0437/0300/9434/files/76039022084.pdf
    • https://cdn.shopify.com/s/files/1/0431/7249/5519/files/40300812272.pdf
    • https://cdn.shopify.com/s/files/1/0432/0028/2783/files/dalipifosedixatijimi.pdf
    • https://cdn.shopify.com/s/files/1/0430/5806/9655/files/71185753613.pdf
    • https://cdn.shopify.com/s/files/1/0428/1604/5222/files/xufotafaxesejurozuwopim.pdf
    • https://cdn.shopify.com/s/files/1/0440/3177/0789/files/ruzagonazono.pdf
    • https://cdn.shopify.com/s/files/1/0428/5962/6655/files/pengendalian_nyamuk_anopheles.pdf
    • https://cdn.shopify.com/s/files/1/0429/5399/8487/files/carboprost_davis_drug_guide.pdf
    • https://cdn.shopify.com/s/files/1/0431/0391/2098/files/basic_division_worksheets_for_grade_1.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b05b.bin
9c51bd803895556eb8d4dd04f80679c8730238b9ae15f4dce9b83bf889620c1d
pdf-font-stream PDF embedded font (sfnt) at offset 0xB05B 5092 bytes
font_01_sfnt_off0000c199.bin
8ddd641ac493c3abc9de1414808f508cd830b64212de69fc8acb6584d6fe61cf
pdf-font-stream PDF embedded font (sfnt) at offset 0xC199 13568 bytes