Malicious PDF — malware analysis report

Static analysis result for SHA-256 405ebbdf1d6abd6d…

MALICIOUS

PDF

37.9 KB Created: 2020-08-12 18:48:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 017f770f75e35df8fc82db3311e8fcdc SHA-1: ae45a7d858d31e1de92404c4c2e242b447484fd4 SHA-256: 405ebbdf1d6abd6dfc06baae8d4b829505988984b832b716899e10e1465b4ea1
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of embedded links, with a critical heuristic firing for a malicious redirector. The ML classifier also strongly indicated maliciousness. The primary malicious IOC is the redirector URL, which likely leads to further malicious content. The document body appears to be malformed or heavily obfuscated, preventing a clear understanding of its user-facing purpose beyond the presence of links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=causative+exercises+advanced+pdf
    • http://files.northwoodshaman.com/uploads/1/3/1/8/131857115/3ae3c70.pdf
    • http://files.kentuckysocietyforrespiratorycare.org/uploads/1/3/1/4/131453256/kudata.pdf
    • http://files.shermanoakstherapyandrecovery.net/uploads/1/3/2/6/132683252/fasesudubuwupo_negikoziwobij_lezokodotirup_dosudalojuf.pdf
    • http://files.genarospizza.com/uploads/1/3/0/9/130969999/2685ae.pdf
    • http://files.baycityenergysmart.org/uploads/1/3/1/4/131452799/09e12fc7a1258a4.pdf
    • https://cdn.shopify.com/s/files/1/0435/1049/7434/files/safosarujesetef.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/nezax.pdf
    • https://cdn.shopify.com/s/files/1/0431/3094/5693/files/doctrine_of_stare_decisis.pdf
    • https://cdn.shopify.com/s/files/1/0446/6016/2713/files/26530746856.pdf
    • https://cdn.shopify.com/s/files/1/0433/2801/2456/files/62663842689.pdf
    • https://cdn.shopify.com/s/files/1/0429/1877/2903/files/ginojixe.pdf
    • https://cdn.shopify.com/s/files/1/0427/7947/6134/files/analytical_methods_in_structural_engineering_by_sarwar_alam_raz.pdf
    • https://cdn.shopify.com/s/files/1/0430/5800/4117/files/jarug.pdf
    • https://cdn.shopify.com/s/files/1/0434/7114/3078/files/wuzovedubogejumowuba.pdf
    • https://cdn.shopify.com/s/files/1/0433/6674/4216/files/python_trim_string.pdf
    • https://cdn.shopify.com/s/files/1/0433/5350/5946/files/43047271616.pdf
    • https://cdn.shopify.com/s/files/1/0430/2870/9539/files/97626673197.pdf
    • https://cdn.shopify.com/s/files/1/0429/4891/9450/files/zesib.pdf
    • https://cdn.shopify.com/s/files/1/0431/6862/8890/files/befol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0429/4891/9450/files/ze

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000055e8.bin
4f0e250f9f50c81fb134885d196c943e836a482bfe1b6625f9dd8b53846b65fd
pdf-font-stream PDF embedded font (sfnt) at offset 0x55E8 5152 bytes
font_01_sfnt_off00006788.bin
afe3998da996a5de7c4d2026b8b27110daf01a47e2ddc93fa25e606e38a3e9f7
pdf-font-stream PDF embedded font (sfnt) at offset 0x6788 10248 bytes