Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f800e1da140591b…

MALICIOUS

PDF

129.2 KB Created: 2020-08-10 11:29:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f6b04f4a9c330e9710eed80b6d889689 SHA-1: 6b1a0cdf566adcefcab15ba7866b2072faced27e SHA-256: 0f800e1da140591b84f8c538cee43d538ec26bbedb712e634a28d6b19f4050a0
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF document impersonates a cloud file-sharing service, a common lure for phishing attacks. It contains a malicious redirector link that leads to a farm of numerous other PDF files, likely intended to obscure the ultimate malicious destination. The ML classifier strongly indicated maliciousness, and the presence of embedded URLs and the document lure support a phishing attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cloud document impersonation lure medium SE_CLOUD_DOC_LURE
    Document impersonates a cloud file-sharing service such as SharePoint, OneDrive, Google Drive, Dropbox, Box, or Microsoft 365 and asks the user to open, verify, or access a shared document
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=simple+definition+of+internet+pdf
    • http://files.biophysical-ecology.com/uploads/1/3/1/4/131406356/xivut_girusidusowele_finusagon.pdf
    • http://files.drycreekgeneralstore1881.com/uploads/1/3/0/9/130969726/5a0a1154a039f7.pdf
    • http://files.thecooleygallery.com/uploads/1/3/0/7/130776602/78100b.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0433/2634/1272/files/33202053313.pdf
    • https://cdn.shopify.com/s/files/1/0431/7990/1085/files/kitiragesefepoxatupagur.pdf
    • https://cdn.shopify.com/s/files/1/0440/5349/5958/files/ejercicios_resueltos_alcanos_alquenos_y_alquinos.pdf
    • https://cdn.shopify.com/s/files/1/0429/1022/0447/files/mathematics_all_symbols_name.pdf
    • https://cdn.shopify.com/s/files/1/0430/3680/3233/files/goxenilifafagisuzewasujig.pdf
    • https://cdn.shopify.com/s/files/1/0433/6022/3382/files/12978978469.pdf
    • https://cdn.shopify.com/s/files/1/0434/7261/7637/files/89860756775.pdf
    • https://cdn.shopify.com/s/files/1/0429/3178/1791/files/rawurolojefabe.pdf
    • https://cdn.shopify.com/s/files/1/0434/1573/2376/files/89122096272.pdf
    • https://cdn.shopify.com/s/files/1/0433/8188/3030/files/86514883806.pdf
    • https://cdn.shopify.com/s/files/1/0439/4693/4430/files/namavixemopiwinosin.pdf
    • https://cdn.shopify.com/s/files/1/0440/3753/7942/files/kanujomevojowirapozavon.pdf
    • https://cdn.shopify.com/s/files/1/0430/2438/4154/files/interior_design_proposal_template.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001b944.bin
14f78b81006d96aa52ee012f45885bd6f9a51ee29f7cee61271c13588969bc79
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B944 4904 bytes
font_01_sfnt_off0001c9dd.bin
ac3986fa5cd8553f3dfe06a4a7ada350f9771e31a9b14f356a6dfaf39d3782f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C9DD 14168 bytes