Malicious PDF — malware analysis report

Static analysis result for SHA-256 432b6240dde2dcc4…

MALICIOUS

PDF

72.8 KB Created: 2020-08-16 12:11:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 09c644dd680bf4497374f772190d5cb8 SHA-1: d929103a1149d710b387357d6578a37e1364fec0 SHA-256: 432b6240dde2dcc463fd4b2f7e92ea095bd62f3a69ce37008afb24697c49a3fa
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains embedded links that redirect to a malicious URL, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though heavily obfuscated, contains text related to a 'vertical axis wind turbine project report pdf' and includes the malicious redirector URL. The ML classifier also strongly flagged this PDF as malicious. The primary attack vector appears to be social engineering through a deceptive link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=vertical+axis+wind+turbine+project+report+pdf
    • http://xovuba.dmcipropertyfinder.com/uploads/1/3/2/6/132681337/pibomova_rujisosewuwidez_jufowebejelasi_makavifixulurus.pdf
    • http://files.bhwhemptherapy.com/uploads/1/3/0/9/130969278/2eeb997ba.pdf
    • http://files.artistmichaelbond.com/uploads/1/3/1/3/131381799/pobalevuliji.pdf
    • https://cdn.shopify.com/s/files/1/0432/5123/7032/files/xewosavenuvasuponukik.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/pekazojifedabefotekufof.pdf
    • https://cdn.shopify.com/s/files/1/0428/6975/1967/files/6725564026.pdf
    • https://cdn.shopify.com/s/files/1/0433/7513/2824/files/algorithme_ppcm.pdf
    • https://cdn.shopify.com/s/files/1/0448/0398/1463/files/xodizuriwudebewodudunu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0012/6885/files/fedisosemo.pdf
    • https://cdn.shopify.com/s/files/1/0429/6212/4959/files/71168626282.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/18983443830.pdf
    • https://cdn.shopify.com/s/files/1/0430/1104/7575/files/61069081145.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000df29.bin
d9b7265e4cafe867c6c30ae49d9e3eb6d91fe0e81e9e3e6a5a1ed4ada1d7d15b
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF29 5492 bytes
font_01_sfnt_off0000f1ee.bin
e5a6dd4af8a1ab190616efc3a252ebdaa8a1f131da195066ccf31caf40030469
pdf-font-stream PDF embedded font (sfnt) at offset 0xF1EE 10660 bytes