Malicious PDF — malware analysis report

Static analysis result for SHA-256 27d4bc117d327e80…

MALICIOUS

PDF

44.0 KB Created: 2020-08-12 06:05:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2503c068d9d06910544feb1725c09853 SHA-1: ad77b342d32d5f5d7e21694e9ad0f791f4bd72b9 SHA-256: 27d4bc117d327e803548572408ad0e82d6c2461fd41e555dd1bdee0b0fe66d2b
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains embedded links that redirect to a known malicious domain, indicating a phishing or redirection attempt. The ML classifier strongly flagged this PDF as malicious. The document body, though partially corrupted, contains text related to 'content validity and reliability' and includes the malicious redirector URL, suggesting a lure to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9987

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=content+validity+and+reliability+of+single+items+or+questionnaires+pdf
    • http://files.starlitelabradors.com/uploads/1/3/2/8/132814930/zojinufeta-megifariz.pdf
    • http://files.euroconferences.org/uploads/1/3/1/0/131070152/zefajazaxose-lanitazudop-miwabokegod-fotito.pdf
    • http://files.younglifemanateecounty.com/uploads/1/3/1/3/131383924/1960506.pdf
    • http://files.bellamachines.com/uploads/1/3/1/3/131380466/muwiwo_zugawobixade_pumusunazo.pdf
    • http://files.my-lhd.com/uploads/1/3/1/6/131606291/berapem-benuxar-kexakipud.pdf
    • https://cdn.shopify.com/s/files/1/0431/7403/5607/files/bouddhisme_de_nichiren.pdf
    • https://cdn.shopify.com/s/files/1/0431/0348/6103/files/rewonetib.pdf
    • https://cdn.shopify.com/s/files/1/0427/5650/5756/files/kesazifunovodiz.pdf
    • https://cdn.shopify.com/s/files/1/0451/8104/2839/files/bhagavath_geetha_malayalam_download.pdf
    • https://cdn.shopify.com/s/files/1/0451/1770/2298/files/63526135606.pdf
    • https://cdn.shopify.com/s/files/1/0430/9221/3911/files/61118599887.pdf
    • https://cdn.shopify.com/s/files/1/0434/5207/2086/files/70247186956.pdf
    • https://cdn.shopify.com/s/files/1/0434/5122/0120/files/57622935270.pdf
    • https://cdn.shopify.com/s/files/1/0429/6415/6582/files/38245416987.pdf
    • https://cdn.shopify.com/s/files/1/0429/8624/2201/files/wexelagazeboxu.pdf
    • https://cdn.shopify.com/s/files/1/0432/4635/4592/files/zoxujokuvi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006c37.bin
6e97c0f3da253f73eb4e793235cd04119ce39f2b47182664a34d010dfa286341
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C37 5696 bytes
font_01_sfnt_off00007f7c.bin
62b9ed724510eb7092b9fec88f8ebe6463bdf1f97b3589514497f550c87d74b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F7C 10144 bytes