Malicious PDF — malware analysis report

Static analysis result for SHA-256 467ddc9fdc494484…

MALICIOUS

PDF

109.5 KB Created: 2020-08-08 07:21:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 18bce2fc4339f48b3680d31b3d8f33c8 SHA-1: 137cf4b697efe81d434893f1fd3bbcd97f632cbe SHA-256: 467ddc9fdc4944844a42d89d0b8ff8cdf577033c4242fec4dc86e0bb50b94962
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous embedded links, with a critical heuristic identifying a link to a known malicious redirector at 'https://ttraff.cc/pify?keyword=chaos+knights+40k+codex+pdf+vk'. The document body, though heavily obfuscated, also contains this URL, suggesting the primary intent is to redirect users to malicious infrastructure. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=chaos+knights+40k+codex+pdf+vk
    • http://files.kelownanaturopathicdoctor.ca/uploads/1/3/1/0/131070152/wutomifeligenixorod.pdf
    • http://files.gretelparker.com/uploads/1/3/1/0/131070851/c8d9dca8aa.pdf
    • http://files.indiecounterculture.com/uploads/1/3/2/6/132695701/bexobeni.pdf
    • http://files.hartfund.org/uploads/1/3/1/3/131384156/losididolura.pdf
    • http://files.bridgeandcivil.com/uploads/1/3/0/8/130813427/38e30.pdf
    • https://cdn.shopify.com/s/files/1/0430/6714/6397/files/iii_convenio_de_ginebra_1949.pdf
    • https://cdn.shopify.com/s/files/1/0430/4188/2265/files/70525138777.pdf
    • https://cdn.shopify.com/s/files/1/0439/2743/7467/files/pawokiduvusibo.pdf
    • https://cdn.shopify.com/s/files/1/0434/7199/5030/files/14404464901.pdf
    • https://cdn.shopify.com/s/files/1/0430/9526/1348/files/tulirikulibepipabamef.pdf
    • https://cdn.shopify.com/s/files/1/0430/8343/2096/files/xetilojenufo.pdf
    • https://cdn.shopify.com/s/files/1/0430/3290/3829/files/novoduwogiwufugapedosak.pdf
    • https://cdn.shopify.com/s/files/1/0428/4933/7507/files/tevafosovukotana.pdf
    • https://cdn.shopify.com/s/files/1/0428/6555/7670/files/download_trigonometry_and_analytical_geometry.pdf
    • https://cdn.shopify.com/s/files/1/0430/5374/4279/files/medonotuw.pdf
    • https://cdn.shopify.com/s/files/1/0427/8996/1884/files/ronenanuxozulawugize.pdf
    • https://cdn.shopify.com/s/files/1/0432/7348/6496/files/witikimevi.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/13977390730.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000170b0.bin
b198c64e969e111a76a03c6717e2decc70cb385568b3d738ab38367914fc3a70
pdf-font-stream PDF embedded font (sfnt) at offset 0x170B0 5616 bytes
font_01_sfnt_off000183e2.bin
99dbd35bccd6eaa84e016541a8d2804386a4cf201fc25e2b4b765d59a1639ae0
pdf-font-stream PDF embedded font (sfnt) at offset 0x183E2 10816 bytes