Malicious PDF — malware analysis report

Static analysis result for SHA-256 91310ea570c2fd55…

MALICIOUS

PDF

65.5 KB Created: 2020-07-10 21:03:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ee7e6a617f3e1d68d0ae45714df9ef32 SHA-1: e79ac2db6c92089da3ac0d47f21c4b375f3808cc SHA-256: 91310ea570c2fd55a6b5e63551a9e7a361ba29bd5044ae0b9665b4fbcee2d018
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous embedded links, many of which point to known malicious redirectors or link farms designed to obscure the final destination. The ML classifier strongly indicated maliciousness. The primary attack pattern involves luring the user into clicking these links, which likely leads to further malicious content or exploits. No scripts were extracted, so the attack relies solely on the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=procimax%20bula%20pdf
    • http://files.drchrisphillips.com/uploads/1/3/1/4/131411411/3602257.pdf
    • http://files.yunialores.com/uploads/1/3/1/6/131606146/525996.pdf
    • http://files.lisabuckpottery.com/uploads/1/3/1/6/131606670/e8ac918a26e3257.pdf
    • http://files.socialgracesweddings.com/uploads/1/3/0/8/130874647/miputi-mobulen.pdf
    • http://files.slightlyaskewphotography.com/uploads/1/3/1/6/131606298/gilivudov_gufazubunisazen.pdf
    • http://files.bpoelks411.org/uploads/1/3/1/6/131636772/5992647.pdf
    • http://files.counsellingpsychologist.services/uploads/1/3/0/9/130969555/7582248.pdf
    • http://files.tmwsports.co.uk/uploads/1/3/0/7/130775391/70cdf9a46db0a5.pdf
    • http://files.filmclub62.com/uploads/1/3/2/6/132681826/romomiwotixev.pdf
    • https://joxaloli.files.wordpress.com/2020/06/63525977554.pdf
    • https://wunoxeroxi64682965.files.wordpress.com/2020/06/gamefupobakuxopexufigedev.pdf
    • https://bozumar.files.wordpress.com/2020/06/25263369298.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/pitoparejiki.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/85947343199.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/37263727017.pdf
    • https://cdn.shopify.com/s/files/1/0429/8699/5863/files/tepobudataka.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c247.bin
506ce562030b862709b2fc7b6d511894396e91e6e9bbfa50fa63810721b0b99d
pdf-font-stream PDF embedded font (sfnt) at offset 0xC247 4912 bytes
font_01_sfnt_off0000d2e4.bin
510b91fc5e1962d38ee94c7135a2398b875dbf47a18593730e50219c1af0b0d8
pdf-font-stream PDF embedded font (sfnt) at offset 0xD2E4 11328 bytes