Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a9d51b3358b963d…

MALICIOUS

PDF

37.3 KB Created: 2020-08-24 00:27:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a8f0e9b341e858d8e6b0bdf88b17d3a4 SHA-1: f1f25dc77fc6d7dbae075af998511ec5e662592f SHA-256: 9a9d51b3358b963d465694993688febda792705664fa346dc1c66ee948e64867
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, many of which point to potentially malicious redirectors or link farms. The document body, though partially corrupted, contains text related to 'Tamil thriller movies 2018 hd' and a URL that appears to be a redirector. This suggests a social engineering tactic to lure users to malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=tamil+thriller+movies+2018+hd
    • http://wopube.dslvnjny.com/uploads/1/3/2/6/132696056/18b0ff5.pdf
    • http://dametobu.13thdistrictofohio.org/uploads/1/3/1/0/131069766/polazizanuf_dumamijija.pdf
    • http://kutug.ohioarea14.org/uploads/1/3/2/6/132683071/xufuparevugupi-gozalesafotusab.pdf
    • http://files.eaadventures.com/uploads/1/3/1/4/131407029/vakojonafikamamajuj.pdf
    • http://punixije.sofitaphotography.com/uploads/1/3/0/9/130969858/1613638.pdf
    • https://cdn.shopify.com/s/files/1/0431/8697/8984/files/90339745997.pdf
    • https://cdn.shopify.com/s/files/1/0430/5921/6537/files/ganobimewari.pdf
    • https://cdn.shopify.com/s/files/1/0433/4652/6361/files/90119819097.pdf
    • https://cdn.shopify.com/s/files/1/0436/3422/9398/files/mivevevud.pdf
    • https://cdn.shopify.com/s/files/1/0431/5719/2853/files/agad_bam_nagada_song.pdf
    • https://cdn.shopify.com/s/files/1/0434/2045/0972/files/google_drive_limit_exceeded.pdf
    • https://cdn.shopify.com/s/files/1/0448/1790/7874/files/ejercicios_resueltos_de_centro_de_gravedad_y_centroide.pdf
    • https://cdn.shopify.com/s/files/1/0429/4731/3827/files/wofunuvibokidejokawowatuk.pdf
    • https://cdn.shopify.com/s/files/1/0427/9291/1007/files/xobusatefezesozasef.pdf
    • https://cdn.shopify.com/s/files/1/0433/7437/9164/files/62030900064.pdf
    • https://cdn.shopify.com/s/files/1/0439/3972/5470/files/39068729128.pdf
    • https://cdn.shopify.com/s/files/1/0427/7701/8524/files/2_minutes_to_midnight_tab.pdf
    • https://cdn.shopify.com/s/files/1/0436/9196/6617/files/17069956291.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000053be.bin
90fa287ff7a4af7f26ae0a051fe0d8cdf60c4c2d91888624b609958d0ba7b970
pdf-font-stream PDF embedded font (sfnt) at offset 0x53BE 5596 bytes
font_01_sfnt_off0000669f.bin
1f2e6574b127f9c7709158dda343133f0c79f989505af6c5795d96f66dd542bd
pdf-font-stream PDF embedded font (sfnt) at offset 0x669F 9764 bytes