Malicious PDF — malware analysis report

Static analysis result for SHA-256 a117161a474a52ef…

MALICIOUS

PDF

37.8 KB Created: 2020-08-19 19:49:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: af8cf304b1de1d419f45c74e4f061de3 SHA-1: 34ae7c52f841e5afa5245f3f1b6986b636b57e44 SHA-256: a117161a474a52ef5706b1bb9ec19ef6bdaad4ce1b95b826c0835b80be766e02
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded links, with one specifically identified as a malicious redirector pointing to a Minecraft APK download. The document body, though heavily obfuscated, contains text fragments related to 'Minecraft pe vn 0. 15. 2 apk', reinforcing the lure. The presence of a PDF link farm and ML classification further support the malicious nature of this document.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=minecraft+pe+vn+0.+15.+2+apk
    • http://files.kinematicintegration.com/uploads/1/3/1/4/131438835/287e220ad0e61.pdf
    • http://guvefap.ndsportschannel.com/uploads/1/3/1/3/131379478/wusogepesifefe-timevijatefa-tilijipozoki-xiwawaxariduki.pdf
    • http://files.hannahchambers.net/uploads/1/3/1/6/131636954/buzitimomuf.pdf
    • https://cdn.shopify.com/s/files/1/0427/4126/8647/files/business_intelligence_systems.pdf
    • https://cdn.shopify.com/s/files/1/0436/7712/2713/files/49824330546.pdf
    • https://cdn.shopify.com/s/files/1/0433/8450/4474/files/53558345196.pdf
    • https://cdn.shopify.com/s/files/1/0431/4651/0504/files/stein_complex_analysis.pdf
    • https://cdn.shopify.com/s/files/1/0431/7154/5237/files/xelabopinexixaxumad.pdf
    • https://cdn.shopify.com/s/files/1/0431/2684/9697/files/31787292975.pdf
    • https://cdn.shopify.com/s/files/1/0434/5446/4165/files/reralujomefugeguva.pdf
    • https://cdn.shopify.com/s/files/1/0438/4640/2213/files/98921741485.pdf
    • https://cdn.shopify.com/s/files/1/0429/9243/5359/files/sipijuwilupimitudosi.pdf
    • https://cdn.shopify.com/s/files/1/0430/6993/1673/files/79602876392.pdf
    • https://cdn.shopify.com/s/files/1/0447/1455/7596/files/64942108828.pdf
    • https://cdn.shopify.com/s/files/1/0433/7005/3784/files/39285662680.pdf
    • https://cdn.shopify.com/s/files/1/0436/8600/2838/files/vonutivexuditopime.pdf
    • https://cdn.shopify.com/s/files/1/0434/8015/4269/files/anti_ragging_online_form.pdf
    • https://cdn.shopify.com/s/files/1/0427/9799/0055/files/sokikarutoka.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000054ed.bin
6b183c75340f41f16ff972c112d79bc2416d1426b7cfa896a300fcd6e8719aa7
pdf-font-stream PDF embedded font (sfnt) at offset 0x54ED 5412 bytes
font_01_sfnt_off00006780.bin
d499d6645b5efb2941ba2a1442995dc547585e26a2ec3863ff8df1b4a1efeff6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6780 10336 bytes