Malicious PDF — malware analysis report

Static analysis result for SHA-256 2e6cf482bb8eaa80…

MALICIOUS

PDF

65.1 KB Created: 2020-07-08 15:00:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cacbbab818b387c98793f9055d2d6f95 SHA-1: f8f0455f442a592bfc241f4fcd7c236330847f5f SHA-256: 2e6cf482bb8eaa80dc2f3102e6eff59025e4e835cda74c2e76f0a5723c4a3567
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains multiple embedded links, with one specifically pointing to a known malicious redirector. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains the same redirector URL, suggesting the primary purpose is to lure the user to malicious infrastructure. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=cyclotron%20frequency%20pdf
    • http://files.brushandbranch.co/uploads/1/3/0/7/130740344/2297158.pdf
    • http://files.summasportswear.com/uploads/1/3/1/4/131453807/118d8e22a22790b.pdf
    • http://files.thefeltfactory.co.nz/uploads/1/3/0/7/130776841/xizixexa-dajawotubep-fekifomidele.pdf
    • http://files.eriwonders.com/uploads/1/3/1/3/131380953/c9ef7.pdf
    • http://files.jimgymsupply.com/uploads/1/3/0/9/130969532/633868.pdf
    • http://files.thecyphersdenradio.com/uploads/1/3/1/3/131398591/e4b85c15.pdf
    • http://files.thediscoverypoint.com/uploads/1/3/2/3/132303060/ee78cb97c.pdf
    • http://files.friendsoftheriverbanks.org/uploads/1/3/1/0/131070379/tolajidatik.pdf
    • http://files.savememagnets.com/uploads/1/3/0/7/130775838/koxupimatagopu-zizapufolulu-kukosavobaxit-pinesid.pdf
    • http://files.burnetcountyhighlandlakesmastergardener.org/uploads/1/3/1/4/131438150/da4ccc942.pdf
    • http://files.carsontidwell.com/uploads/1/3/1/4/131438249/mumiv.pdf
    • http://files.shannondrhodes.com/uploads/1/3/0/8/130873907/1944747.pdf
    • http://files.friendsoftheriverbanks.org/uploads/1/3/1/0/
    • https://gefulinosug650871460.files.wordpress.com/2020/06/xawevozenapexom.pdf
    • https://dipajar.files.wordpress.com/2020/06/sunekazeponolesupedaviw.pdf
    • https://gakijisib.files.wordpress.com/2020/07/sirukuzuwotelipemapadekex.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ac00.bin
ef7ba75c09333ca90b49ee6393fa65aa7509e8c033e0c962a6d3c9e92e959b5f
pdf-font-stream PDF embedded font (sfnt) at offset 0xAC00 4848 bytes
font_01_sfnt_off0000bc89.bin
ce9a285c44bd499cba89b7ba202ff81cc6d0d96357c196a98d805772a0befa75
pdf-font-stream PDF embedded font (sfnt) at offset 0xBC89 10932 bytes
font_02_sfnt_off0000e1ac.bin
1dcd9cd0ede1399b22fe02817bf9ba234d19a32d80395d147cb5dc32702988d8
pdf-font-stream PDF embedded font (sfnt) at offset 0xE1AC 16416 bytes