Malicious PDF — malware analysis report

Static analysis result for SHA-256 40f5d69a8adb0eee…

MALICIOUS

PDF

77.7 KB Created: 2020-09-04 00:02:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fa064382763ec9657150902147311129 SHA-1: 9bea1eedc072a8eb9d649a6bf49d17facab10811 SHA-256: 40f5d69a8adb0eee3c77defa7e2a18a7b9bb8a94e6e7a10488259fe316d6f087
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous links, including one identified as a malicious redirector. The document body, though heavily obfuscated, contains text related to 'multivariate exponential distribution pdf' and the malicious URL. This suggests the document is designed to trick users into clicking the malicious link under the guise of a legitimate PDF, likely leading to further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=multivariate+exponential+distribution+pdf
    • https://cdn.shopify.com/s/files/1/0431/6561/4234/files/statistics_formulas_with_examples.pdf
    • https://cdn.shopify.com/s/files/1/0444/8436/2407/files/building_the_analysis_model_in_software_engineering.pdf
    • https://cdn.shopify.com/s/files/1/0430/0003/7527/files/cbse_class_10_sample_paper_2020_maths.pdf
    • https://cdn.shopify.com/s/files/1/0432/9799/6955/files/square_magazine_mockup_psd_free.pdf
    • https://static.usrfiles.com/ugd/fd30ac_cba3077f309f41df9ccf8dd966c34925.pdf
    • https://static.usrfiles.com/ugd/599026_bf1789f4b03e4e88b5b017f01551d258.pdf
    • https://static.usrfiles.com/ugd/fa6f14_21f42402357241a4aacc7132a645528f.pdf
    • https://static.usrfiles.com/ugd/30ea26_db97ff0284ed443ea19ae7288b90f69a.pdf
    • https://static.usrfiles.com/ugd/8e9e2f_605dc9421a2d4cb8902e9d97cd1bf139.pdf
    • https://static.usrfiles.com/ugd/a48928_6abf0351dc1f4dd483db9a95046f3e69.pdf
    • https://static.usrfiles.com/ugd/2e16aa_18517460e85e4da2a3b01d03dfd1d70d.pdf
    • https://static.usrfiles.com/ugd/fb5067_e39c4af0ab4f4c91a5322cdcb6f8a1b2.pdf
    • https://static.usrfiles.com/ugd/67e251_5acdf33e8bc548e6b6c1f8db06b28e08.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c372.bin
3cb80eeeb036be62996e9cd48ef6f5198a33bdc1aaa49ffbec247c4db2398f60
pdf-font-stream PDF embedded font (sfnt) at offset 0xC372 5308 bytes
font_01_sfnt_off0000d59b.bin
1ea7af43cba68bcdcf3b2bb45bd917cf0d63e13d608d9814bb042201310af692
pdf-font-stream PDF embedded font (sfnt) at offset 0xD59B 18232 bytes
font_02_sfnt_off00010f4e.bin
e45b42064cd21c78a03ca51010c9e82c747eb12a1b0a43d91b7bfd71610fbc49
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F4E 16808 bytes