Malicious PDF — malware analysis report

Static analysis result for SHA-256 612663f5f0476976…

MALICIOUS

PDF

44.3 KB Created: 2020-08-23 09:03:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 220261e6a02960ff73e951a205347ef5 SHA-1: f240b2dd171e4cd6c81366645ca39c8024dcccf5 SHA-256: 612663f5f04769767ae2345704c02d03ff4dbe179ccb28006b9b99fe98f046fd
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains embedded links that redirect to malicious infrastructure, specifically a URL designed to appear as an answer key. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK confirms the malicious nature of the primary redirector. The ML classifier also strongly indicates maliciousness. The document body, though obfuscated, contains text related to an answer key and the malicious URL, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=answer+key+for+10+maths+2019
    • http://files.healthypathinc.com/uploads/1/3/0/7/130776366/7892926.pdf
    • http://zudul.alyssarcieri.com/uploads/1/3/0/7/130738902/30bbb3.pdf
    • http://files.sonomacountycagers.com/uploads/1/3/1/4/131453735/8295339.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0434/3011/7526/files/6730934030.pdf
    • https://cdn.shopify.com/s/files/1/0437/7070/8129/files/libro_el_aprendiz_de_brujo_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0431/3320/6690/files/77958311421.pdf
    • https://cdn.shopify.com/s/files/1/0431/0610/7552/files/busas.pdf
    • https://cdn.shopify.com/s/files/1/0460/9608/9252/files/misemepazowitaloweruw.pdf
    • https://cdn.shopify.com/s/files/1/0431/2737/3990/files/halloween_math_worksheets_for_preschoolers.pdf
    • https://cdn.shopify.com/s/files/1/0431/0741/8274/files/antenatal_screening_guidelines_uk.pdf
    • https://cdn.shopify.com/s/files/1/0438/1632/1184/files/84525154986.pdf
    • https://cdn.shopify.com/s/files/1/0438/2051/5488/files/airtel_voice_call_app.pdf
    • https://cdn.shopify.com/s/files/1/0433/1094/0328/files/acing_the_interview.pdf
    • https://cdn.shopify.com/s/files/1/0437/7876/9045/files/legendary_game_of_heroes_f2p_guide.pdf
    • https://cdn.shopify.com/s/files/1/0436/4143/8366/files/upkar_publication_book_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006cd5.bin
fb3ee3e6bac8693a92cac844e30342909c0b280720a32f1b95b3d081984942a4
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CD5 5704 bytes
font_01_sfnt_off0000802b.bin
83ede15cd597707dd452de69badc6b4e984b1e0f9838e5cfb7cace7a195ee376
pdf-font-stream PDF embedded font (sfnt) at offset 0x802B 10736 bytes