Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c52f63960fe690a…

MALICIOUS

PDF

42.5 KB Created: 2020-09-18 06:46:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8e4a972ec5f24429541f878910f6c607 SHA-1: 19e5468d54136363bc94550d6d4ef7a1d78d1076 SHA-256: 5c52f63960fe690a9ed0adcd55cb0aecfa64ad2f4fcaf9e4df00fb5259ea8973
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to a redirector URL identified as malicious. The document body, though heavily obfuscated, contains text suggesting it is a worksheet answer key, likely a lure to encourage clicks on the malicious links. The presence of embedded URLs and the ML classifier firing strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=chemistry+reactions+worksheet+answers
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://6d76ef7d-8e03-49bc-be8c-cc1e23a2af20.filesusr.com/ugd/3d514e_e091f056149649ce8468b16e7cce66a7.pdf?index=true
    • https://5813023e-df3c-4941-918e-c83951cfd750.filesusr.com/ugd/2f7489_b0ab2561eea140f0936bed02cdaedd2a.pdf?index=true
    • https://84ab88cb-bb14-48c4-bcd5-36b1a8cd15ff.filesusr.com/ugd/7dfe85_6bd80a05ab5b4fbeb00278b970fda244.pdf?index=true
    • https://6e8c98c5-66cb-4079-b96d-4fb05596901a.filesusr.com/ugd/0049ca_29d3091e193247dba2ee65ea7e017278.pdf?index=true
    • https://0d759238-7e1e-4cec-9d64-f16cdf268709.filesusr.com/ugd/02ccf7_6ffaa140d3624291951c3f1c646259d2.pdf?index=true
    • https://07ed169d-f166-451b-86fe-9bac6989c938.filesusr.com/ugd/54dfea_93b57c22c4ac49b498c384fa1caed2d0.pdf?index=true
    • https://043b033f-1a9a-4ecb-908e-81353e0986f4.filesusr.com/ugd/0df15e_491b5736fe274159b95437038bd889af.pdf?index=true
    • https://e9765cc6-58ad-4b24-994f-7c42b0c5a04d.filesusr.com/ugd/bf57b5_080f0a35c6ea4d37960421e8515ca4c9.pdf?index=true
    • https://498b408a-669f-448f-b732-35b262930ebc.filesusr.com/ugd/23a6c3_3488dee78ea24edcb0d0ea6acbef51b5.pdf?index=true
    • https://4ab9fd42-5bdb-4f4d-b7be-224a3db7d7b8.filesusr.com/ugd/2b25b5_122ca1b7f41e41659d50b2b74347bb76.pdf?index=true
    • https://700406d4-fde8-4470-b7f6-09abbfec2f7b.filesusr.com/ugd/b56239_42f17346d73f4b9ebd520142ad3e0f2d.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0431/3966/1986/files/scholarship_2019_to_2020_india.pdf
    • https://cdn.shopify.com/s/files/1/0435/5719/1843/files/beneficios_de_la_zanahoria.pdf
    • https://cdn.shopify.com/s/files/1/0435/3776/0408/files/fairness_and_accuracy_in_reporting_twitter.pdf
    • https://cdn.shopify.com/s/files/1/0438/2860/9186/files/fofewu.pdf
    • https://cdn.shopify.com/s/files/1/0434/1907/4712/files/hash_table_implementation_in_java.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000069bc.bin
4017f999cc40e085b75d8e6d8ddc10200b8d7ff091d45d36978cfe8b337ddc97
pdf-font-stream PDF embedded font (sfnt) at offset 0x69BC 5172 bytes
font_01_sfnt_off00007b32.bin
85ded28ce680ae20bdfb39df9c35c3af1e863cc934928eb727bc2f9547d21725
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B32 9804 bytes