Malicious PDF — malware analysis report

Static analysis result for SHA-256 6f2c7630c577abfd…

MALICIOUS

PDF

45.5 KB Created: 2020-07-28 02:58:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ee29bcb629ced86be807a3727503fc7b SHA-1: a9ba81e6bfffae68c53ef0529d73c430d700df19 SHA-256: 6f2c7630c577abfd97b2c7ab84fa2dedf3772ac105549b89cdf67ac165e0c3bf
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous links, with one critical heuristic firing indicating it points to known malicious redirector infrastructure. The document body, though obfuscated, suggests a lure related to 'basic commands in unix pdf'. The ML classifier strongly flagged this PDF as malicious, supporting the conclusion that it's designed to redirect users to harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=basic+commands+in+unix+pdf
    • http://files.boomerbones.com/uploads/1/3/1/0/131070842/vuletekufobis.pdf
    • http://files.trojerestaurant.com/uploads/1/3/1/8/131857115/mokapememunu-zelenarixiva.pdf
    • http://files.bigt-farms.com/uploads/1/3/1/6/131606035/f6835af.pdf
    • http://files.efeschoolcounselor.com/uploads/1/3/2/7/132710676/8951229.pdf
    • http://files.transformurlifetoday.com/uploads/1/3/2/6/132695397/2c8bf4ac0e4ee.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0431/8858/4605/files/motomorilebar.pdf
    • https://cdn.shopify.com/s/files/1/0430/0174/1463/files/zugobotuliwobutuwuzarigu.pdf
    • https://cdn.shopify.com/s/files/1/0431/4886/9786/files/ligis.pdf
    • https://cdn.shopify.com/s/files/1/0435/5712/6295/files/jumusarumubuso.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/97253363073.pdf
    • https://cdn.shopify.com/s/files/1/0429/9636/7511/files/xavivigajejubede.pdf
    • https://cdn.shopify.com/s/files/1/0430/4273/4237/files/rufegasir.pdf
    • https://cdn.shopify.com/s/files/1/0429/6045/3791/files/wewuvewabigilujukilesez.pdf
    • https://cdn.shopify.com/s/files/1/0435/2655/3752/files/borebopen.pdf
    • https://cdn.shopify.com/s/files/1/0432/3413/2131/files/kaguzugubo.pdf
    • https://cdn.shopify.com/s/files/1/0431/1446/3394/files/nukuwusagiti.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/todexarim.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007773.bin
82947aa38c8031d6264c8dea1f749880d7ee2706bf373388f51efb1ec43d9fb4
pdf-font-stream PDF embedded font (sfnt) at offset 0x7773 4972 bytes
font_01_sfnt_off00008837.bin
2922e2d772a35cfedefe83dfb3504cc82b2d4f5bd9308b99f18cf90e4428d22e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8837 9600 bytes