Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ef3e7767038c7e8…

MALICIOUS

PDF

48.0 KB Created: 2020-07-26 06:50:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a0685a9d127da1623f5c5e35c1ad8a02 SHA-1: 39eb3a5775c21a0b57d4b306e0dbce82a641eb7e SHA-256: 8ef3e7767038c7e8d79fe45f5f18430c846f6d5a4abff8c7e36c362f0356e779
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a high number of external links, with one pointing to a known malicious redirector. The ML classifier also strongly indicated maliciousness. The document body is heavily obfuscated, but the presence of the 'angsana new for mac' string and the PDF link farm suggest a lure to a malicious site, possibly for phishing or to download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=angsana+new++for+mac
    • http://files.hajrasouliha.com/uploads/1/3/0/7/130739474/79edbd5.pdf
    • http://files.deaempresaconstructora.com/uploads/1/3/2/7/132740692/4df58.pdf
    • http://files.kimhambyart.com/uploads/1/3/1/4/131437778/rimarased-xoturiki-dutujasu-zimuvu.pdf
    • https://cdn.shopify.com/s/files/1/0429/4151/3894/files/11123284284.pdf
    • https://cdn.shopify.com/s/files/1/0438/4797/5062/files/94373274361.pdf
    • https://cdn.shopify.com/s/files/1/0435/3739/9957/files/19483316184.pdf
    • https://cdn.shopify.com/s/files/1/0429/3237/1622/files/gebazevobewatafebuwa.pdf
    • https://cdn.shopify.com/s/files/1/0432/0067/6001/files/lopipope.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/93616534700.pdf
    • https://cdn.shopify.com/s/files/1/0433/6992/2714/files/poworuxegog.pdf
    • https://cdn.shopify.com/s/files/1/0432/7640/2854/files/rugasugamujopenekel.pdf
    • https://cdn.shopify.com/s/files/1/0430/7773/0464/files/kivazufinojurazoxavog.pdf
    • https://cdn.shopify.com/s/files/1/0432/1338/9992/files/bowikesisebezak.pdf
    • https://cdn.shopify.com/s/files/1/0431/0741/8273/files/63276704677.pdf
    • https://cdn.shopify.com/s/files/1/0431/2167/2356/files/33823538613.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/tunamowari.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off00006a5e.bin
0a39f34395d4763ece6531a9067916095f9f11a66fb8d1dac5ca707f17d811c3
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6A5E 10452 bytes
font_00_sfnt_off000059cc.bin
ed4c452936135570f305311b7cefef130fd2f545c2533a79dd1a8caed1ceab8d
pdf-font-stream PDF embedded font (sfnt) at offset 0x59CC 4912 bytes
font_02_sfnt_off00008786.bin
4442d55be73ed198f1d93bf43bcfd4d6add5d92bcfc92a2e670fed32476659d6
pdf-font-stream PDF embedded font (sfnt) at offset 0x8786 13912 bytes