Malicious PDF — malware analysis report

Static analysis result for SHA-256 02c7df02df8dafde…

MALICIOUS

PDF

213.6 KB Created: 2020-08-11 01:16:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0661d2e72fdfa7dc157bb0f1f62765df SHA-1: 97fa509a38a2a074aef20833772aa2d172bbd52c SHA-256: 02c7df02df8dafdebeb57e74a4864c3369187bac79e7c4f9a723757d4a9e00f1
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that is flagged as a malicious redirector. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains the same URL, suggesting it is the primary lure. No scripts were extracted, but the presence of a malicious URL is sufficient to indicate a likely phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=adversus+jovinianum+pdf
    • http://files.erminsinanovic.com/uploads/1/3/2/3/132302998/nofumujoj.pdf
    • http://bovonip.larisamantordressage.com/uploads/1/3/1/6/131607163/2540473.pdf
    • http://files.ninelivestwine.com/uploads/1/3/0/8/130874629/vezik_gunefitotokek.pdf
    • http://befukola.iamcnola.org/uploads/1/3/0/8/130874276/2897580.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0433/1814/9285/files/zadezatesatopokuxele.pdf
    • https://cdn.shopify.com/s/files/1/0434/5564/3813/files/belgian_railway_map.pdf
    • https://cdn.shopify.com/s/files/1/0434/3591/7479/files/adobe_premiere_pro_bangla_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0432/9511/3374/files/pokemon_emerald_codebreaker_codes.pdf
    • https://cdn.shopify.com/s/files/1/0431/6404/1373/files/44624917609.pdf
    • https://cdn.shopify.com/s/files/1/0449/2269/9943/files/slow_cooker_recipes_uk.pdf
    • https://cdn.shopify.com/s/files/1/0439/5152/1947/files/49064055971.pdf
    • https://cdn.shopify.com/s/files/1/0431/5525/9560/files/46290863200.pdf
    • https://cdn.shopify.com/s/files/1/0438/4302/7106/files/fundamentals_of_engineering_thermodynamics_6th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0433/1310/2998/files/48145045956.pdf
    • https://cdn.shopify.com/s/files/1/0431/0636/9703/files/aprendizaje_significativo_en_matematicas.pdf
    • https://cdn.shopify.com/s/files/1/0431/3497/6157/files/mafogijexoker.pdf
    • https://cdn.shopify.com/s/files/1/0432/6971/8182/files/form_593-_e.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/41326774972.pdf
    • https://cdn.shopify.com/s/files/1/0445/4989/8399/files/47831559641.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000305e3.bin
5f0344c5b5af200a858baf68910c693b715686e6344b0230487416f3203a866e
pdf-font-stream PDF embedded font (sfnt) at offset 0x305E3 5280 bytes
font_01_sfnt_off000317ca.bin
1447b683fc745c99e83f631d43b3cf77b90a818a9725663cee65dfcde846cf82
pdf-font-stream PDF embedded font (sfnt) at offset 0x317CA 15764 bytes