Malicious PDF — malware analysis report

Static analysis result for SHA-256 75531a949da20c10…

MALICIOUS

PDF

69.3 KB Created: 2020-08-24 23:21:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2d1c9b2892c28c9593bf3f51fcaef600 SHA-1: b105a99afeaf30b63bbad26aa2bc4eec16121620 SHA-256: 75531a949da20c10a070cf3bde23262646b6bc27125c7a35c4c3627b49d33e38
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link that redirects to malicious infrastructure, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body and embedded URLs suggest a lure related to an assignment, likely intended to trick the user into clicking the malicious link. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9941

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=deled+assignment+front+page+in+tamil+pdf
    • http://files.invernesssouth.com/uploads/1/3/0/7/130776164/saliwumawuwefi_rajoxamad_pekurales_fesaxiz.pdf
    • http://kuzoxed.suite-harmony.com/uploads/1/3/2/7/132740873/d1421.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://www.indictrans.org
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0431/6482/7805/files/84273751345.pdf
    • https://cdn.shopify.com/s/files/1/0437/8161/9861/files/church_of_christ_bible_study_lessons.pdf
    • https://cdn.shopify.com/s/files/1/0430/4424/1562/files/6th_grade_math_worksheets_with_answer_key.pdf
    • https://cdn.shopify.com/s/files/1/0434/1815/7221/files/palladium_rifts_download.pdf
    • https://cdn.shopify.com/s/files/1/0430/4447/0938/files/winizo.pdf
    • https://cdn.shopify.com/s/files/1/0434/7301/0850/files/76990754690.pdf
    • https://cdn.shopify.com/s/files/1/0435/5106/4228/files/affidavit_form_michigan.pdf
    • https://cdn.shopify.com/s/files/1/0434/2136/8472/files/author_s_point_of_view_worksheets.pdf
    • https://cdn.shopify.com/s/files/1/0430/4610/9345/files/dosolu.pdf
    • https://cdn.shopify.com/s/files/1/0436/4900/7769/files/business_process_management_ebook_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/7184/0161/files/95489646440.pdf
    • https://cdn.shopify.com/s/files/1/0438/4777/8469/files/bajoxiv.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular

Extracted artifacts 11

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063ea.bin
5bf1b51bac30211e5486ca0ba0e860befc7fa97c723b9e2df9e5baaf84eabb77
pdf-font-stream PDF embedded font (sfnt) at offset 0x63EA 5148 bytes
font_01_sfnt_off00007550.bin
dbaab8dcf32bfe64cb008f34eb54f5316f62236e8dffe3de49b44225404383a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7550 2656 bytes
font_02_sfnt_off00008052.bin
1e9c0b3d34503cc7681e2109c995b93e80c315ded8ea2be2e9e489a20fd89b84
pdf-font-stream PDF embedded font (sfnt) at offset 0x8052 4944 bytes
font_03_sfnt_off00009069.bin
864cbe2c6973b44d2b71e19ffbffb2328dcb3759b07ceb43c11d5a372fc4956d
pdf-font-stream PDF embedded font (sfnt) at offset 0x9069 2328 bytes
font_04_sfnt_off00009b21.bin
0e4b190990c22158f359a0de2485c61736e93a484cfb226f63bccb9bc1da1b2f
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B21 2604 bytes
font_05_sfnt_off0000a637.bin
d117309382da938f7dffedc42f90dd4217b4d540d75629b80669d975ecbc171e
pdf-font-stream PDF embedded font (sfnt) at offset 0xA637 2108 bytes
font_06_sfnt_off0000b00b.bin
87016e8933cc862d1d188edfbee698abcff8178ed3d6b510b61737ee02f60284
pdf-font-stream PDF embedded font (sfnt) at offset 0xB00B 4336 bytes
font_07_sfnt_off0000bdab.bin
17877a646861d50b23ea59d4ac700015081298389279896793d7f42b5a845f28
pdf-font-stream PDF embedded font (sfnt) at offset 0xBDAB 9708 bytes
font_08_sfnt_off0000def3.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0xDEF3 4324 bytes
font_09_sfnt_off0000ecf5.bin
025538e3588f7b9d3e560964fe9e5c5dd3c522b204bc36b7a61ab4edc9b69206
pdf-font-stream PDF embedded font (sfnt) at offset 0xECF5 2704 bytes
font_10_sfnt_off0000f816.bin
ebc5699c0f42178fc20e76d84ea33a80238507828986975a956b1d0747304360
pdf-font-stream PDF embedded font (sfnt) at offset 0xF816 2608 bytes