Malicious PDF — malware analysis report

Static analysis result for SHA-256 3137f452d172951e…

MALICIOUS

PDF

44.4 KB Created: 2020-08-18 19:02:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 204e2fb2e96c3545ebb132d1ec9e9104 SHA-1: bc931891f1d1473b2e586ac41dbb227f29493a33 SHA-256: 3137f452d172951efeb99241edfbb0cef13bc7d279c4ffa6cf31a93574f94cd3
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm and a specific URL pointing to a redirector, indicating a phishing or scam attempt. The ML classifier strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the malicious URL and other links that appear to be part of a link farm designed to obscure the true destination.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=acids+and+bases+worksheet+ks3
    • http://namojoze.fountainoflifeministrieshavelock.org/uploads/1/3/1/4/131483627/xabanuzu.pdf
    • http://files.cpccedu271.org/uploads/1/3/0/7/130775084/2055206.pdf
    • http://files.twinflamepsychic1111.co.uk/uploads/1/3/1/6/131636984/6324394.pdf
    • https://cdn.shopify.com/s/files/1/0452/7711/8625/files/chomage_en_cas_de_demission_pour_formation.pdf
    • https://cdn.shopify.com/s/files/1/0434/3309/9430/files/besanukudaturasov.pdf
    • https://cdn.shopify.com/s/files/1/0429/2893/0979/files/43217641528.pdf
    • https://cdn.shopify.com/s/files/1/0434/5928/1048/files/dirugafidel.pdf
    • https://cdn.shopify.com/s/files/1/0434/0455/8488/files/36202094270.pdf
    • https://cdn.shopify.com/s/files/1/0437/0595/8553/files/alpha_helix_vs_beta_sheet_amino_acids.pdf
    • https://cdn.shopify.com/s/files/1/0435/2311/3119/files/pikuvuguwalujovajaxe.pdf
    • https://cdn.shopify.com/s/files/1/0431/1610/1781/files/23786838055.pdf
    • https://cdn.shopify.com/s/files/1/0437/2201/4870/files/87035722516.pdf
    • https://cdn.shopify.com/s/files/1/0431/2691/5239/files/kamudowedilejuvonuzu.pdf
    • https://cdn.shopify.com/s/files/1/0434/7763/1126/files/85968744064.pdf
    • https://cdn.shopify.com/s/files/1/0432/7600/9622/files/zupome.pdf
    • https://cdn.shopify.com/s/files/1/0435/2966/6724/files/biology_letters_template.pdf
    • https://cdn.shopify.com/s/files/1/0431/0725/4439/files/15781109941.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004d28.bin
51ae8c3ca8aceeb00a942b77d2d000e6d7eed483f46a553ad5c68d9e618d9988
pdf-font-stream PDF embedded font (sfnt) at offset 0x4D28 5232 bytes
font_01_sfnt_off00005eea.bin
8ca52e24022c06398e27c1a1bdb74187bda248ed7e14fa8a983abfad3b22754c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5EEA 9976 bytes
font_02_sfnt_off00008132.bin
b2ddecaff7e2361bf51021b35f9c014659943b600c4f466cb4656cea9e83b80e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8132 16088 bytes
font_03_sfnt_off000095f2.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x95F2 4324 bytes