Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dad15058b199543…

MALICIOUS

PDF

57.4 KB Created: 2020-08-22 21:06:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e4e6bbc1c641d2b42146d4e91a71f3a0 SHA-1: 7a1456ab78a569408b9ae20965a48d612241c8d3 SHA-256: 9dad15058b199543b0993fa419fc0892b9afc437f384c28f8d6419d086e72d87
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, disguised with a search query for a car manual. The PDF also contains a large number of links to other PDFs hosted on Shopify, likely as part of an SEO link farm to improve search engine ranking for the malicious content. The ML classifier strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=2015+buick+verano+manual+transmission
    • http://files.hatsbyelvee.com/uploads/1/3/1/0/131069887/d4c83ee68cc5e98.pdf
    • http://files.precisiondiecutting.com/uploads/1/3/1/3/131380341/defaveveviz-pizaxe-sovab.pdf
    • http://deraroz.waxent.com.au/uploads/1/3/1/8/131857315/fezunugatinafexo.pdf
    • http://gadominux.amyluckenbill.com/uploads/1/3/1/3/131398020/tewukaj.pdf
    • http://biwad.stmarysclinic.net/uploads/1/3/1/4/131409310/601c672011ce.pdf
    • https://cdn.shopify.com/s/files/1/0440/5955/8053/files/wirilumu.pdf
    • https://cdn.shopify.com/s/files/1/0434/1989/3927/files/zaneguto.pdf
    • https://cdn.shopify.com/s/files/1/0434/2287/5797/files/15671183122.pdf
    • https://cdn.shopify.com/s/files/1/0434/5279/2982/files/phd_thesis_on_leadership_styles.pdf
    • https://cdn.shopify.com/s/files/1/0432/5556/2402/files/waste_management_project.pdf
    • https://cdn.shopify.com/s/files/1/0440/1951/5557/files/13106873958.pdf
    • https://cdn.shopify.com/s/files/1/0430/9581/8404/files/74325110800.pdf
    • https://cdn.shopify.com/s/files/1/0436/6109/9161/files/sibisaxofinufe.pdf
    • https://cdn.shopify.com/s/files/1/0429/2493/3287/files/fonedofiwosowusedonexi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000733e.bin
2169b6d24ec9d231786d4eee80bf0ee9b382b70350b05b99e76c575a3c16e250
pdf-font-stream PDF embedded font (sfnt) at offset 0x733E 7524 bytes
font_01_sfnt_off00008ca3.bin
a6c59c8c95507f54efc3cbae08d4feb4088ea0fc3482c173b65ce2282429f2a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CA3 5564 bytes
font_02_sfnt_off00009f79.bin
240981176981ada0d432b2a6e4e38ab18c0d2c6da6caf9027008b115a8926c00
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F79 10404 bytes
font_03_sfnt_off0000c356.bin
ae97ebdbf5cb6679ee3ae7f6f8963da9ec2437ada1f672a33085bc8cbe806833
pdf-font-stream PDF embedded font (sfnt) at offset 0xC356 16060 bytes