Malicious PDF — malware analysis report

Static analysis result for SHA-256 02eeefee95dcd06d…

MALICIOUS

PDF

161.9 KB Created: 2020-10-26 04:42:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-01
MD5: 997c7f488d8efa885d50de33670fe6ae SHA-1: d8360620c6d422074bf3bc9040c11d1d321cd587 SHA-256: 02eeefee95dcd06d5e5a0d2a16db4e6a9cb8c0ad45dbfe665176ffdcfc15f068
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a malicious redirector link disguised as a search result for educational material. The ML classifier strongly indicated maliciousness, and the heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' confirms the presence of a link to known malicious infrastructure. The document body, though heavily obfuscated, contains the malicious URL and a QR code lure, suggesting a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9729

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/123?keyword=buku+teks+matematik+tingkatan+1+2020+pdf In PDF document text
    • https://xedaliwim.weebly.com/uploads/1/3/1/4/131454603/851994230dcae.pdfIn PDF document text
    • https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/8882364.pdfIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.fontrix.comhttp://www.nhncorp.comIn PDF document text
    • https://s3.amazonaws.com/biwuwukesazef/basic_accounting_journal_entries.pdfIn PDF document text
    • https://s3.amazonaws.com/lokijuronig/celerio_tour_h2_brochure.pdfIn PDF document text
    • https://s3.amazonaws.com/kudufigunabi/58103080776.pdfIn PDF document text
    • https://s3.amazonaws.com/mijedusovineti/1009778212.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0480/7439/1709/files/mazadumugiki.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0504/2064/6048/files/ar_guided_reading_level_conversion_chart.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0493/6115/8300/files/90848755980.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0496/6383/6323/files/shelby_middle_school_michigan.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0478/9174/2886/files/xukovidawafomisowosuma.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0476/8107/7414/files/8949387094.pdfIn PDF document text
    • https://s3.amazonaws.com/fapaga/comparative_and_superlative_adjectives_lesson_plan.pdfIn PDF document text
    • https://s3.amazonaws.com/jinabisura/moputiwiva.pdfIn PDF document text
    • https://s3.amazonaws.com/pizivurapab/zidikuwe.pdfIn PDF document text
    • https://s3.amazonaws.com/wenobagupexekap/7699858116.pdfIn PDF document text
    • https://s3.amazonaws.com/jenagubadopi/iti_book_in_hindi_download.pdfIn PDF document text
    • https://s3.amazonaws.com/rokuwapesu/mozabuwufigadiwukeropo.pdfIn PDF document text
    • https://s3.amazonaws.com/mubefula/alter_ego_4_manuel.pdfIn PDF document text
    • https://s3.amazonaws.com/domegagowevag/40084509627.pdfIn PDF document text
    • https://s3.amazonaws.com/dalava/32749231239.pdfIn PDF document text
    • https://s3.amazonaws.com/tujeviwakirawu/administrative_aide_duties_and_responsibilities.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_008_off000203f6.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x203F6 15456 bytes
SHA-256: 232ea493bfb6a648ff0ba01d837bf08f955d4ed5ce48f5a4d04994ea013b44ba
font_00_sfnt_off0001e68e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1E68E 5672 bytes
SHA-256: 97c9da5ff4e4dc0b6735add03504cea984d4fcd562089cb1d36dc30fc77ff64a
font_01_sfnt_off0001f9d9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1F9D9 2344 bytes
SHA-256: 4485b951fc3303be9abe78844f5bffe0970bf3faf2dd90577c12602f990579ec
font_03_sfnt_off00022eb9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x22EB9 12380 bytes
SHA-256: be11038e0d6ea073664aa22b2fe99bad52c09c508be1e3154b87ce1392b83396
font_04_sfnt_off000258ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x258EC 2132 bytes
SHA-256: e49ef65b791f826c964530b273cc223e6be6dd026b9e5f04a57373d5d89f5ae1
font_05_sfnt_off0002623a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2623A 16072 bytes
SHA-256: 24c5c481937acf4f4841e6563a6d7a18cfdb810806c94b09ac0ff4033348c1e6