Malicious PDF — malware analysis report

Static analysis result for SHA-256 a1e02f1e792b0b65…

MALICIOUS

PDF

55.4 KB Created: 2020-08-10 10:56:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1f869a33f647c1c0560a3ec4423a1323 SHA-1: e7503bea5a528c957ce8f6982e25b499bdc3c3e3 SHA-256: a1e02f1e792b0b65b063fc0ec6b370c9376fdca9d6de00eeda8366194274e439
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a prominent link that redirects to a malicious URL, disguised as a download for 'Some applications of trigonometry class 10 pdf'. This is further supported by heuristics indicating a malicious redirector link and a PDF link farm, suggesting a spam or SEO poisoning campaign. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, but the primary attack vector is the embedded malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=some+applications+of+trigonometry+class+10+pdf+download
    • http://files.lauramorrisonwrites.com/uploads/1/3/2/7/132741476/2321461.pdf
    • http://files.scsalc.org/uploads/1/3/0/8/130813732/mugulojiruxuweb-mezijarovigi-wukebitive.pdf
    • http://files.riscooper.com/uploads/1/3/1/4/131437402/61d496c28.pdf
    • http://files.redesignforwholefamilies.com/uploads/1/3/1/8/131857193/jowudakavesof-rusodisoton-zofokizubolas.pdf
    • http://rosejaxaj.ulrichhoeche.com/uploads/1/3/0/7/130740072/057392a.pdf
    • https://cdn.shopify.com/s/files/1/0429/4747/7660/files/20508855406.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/25346701784.pdf
    • https://cdn.shopify.com/s/files/1/0431/3264/9636/files/99613788509.pdf
    • https://cdn.shopify.com/s/files/1/0430/3477/1610/files/google_stun_servers.pdf
    • https://cdn.shopify.com/s/files/1/0433/1326/6846/files/72689399403.pdf
    • https://cdn.shopify.com/s/files/1/0433/4164/3928/files/26752683270.pdf
    • https://cdn.shopify.com/s/files/1/0440/7027/3174/files/farewell_speech_examples.pdf
    • https://cdn.shopify.com/s/files/1/0438/1406/0189/files/42894107358.pdf
    • https://cdn.shopify.com/s/files/1/0432/1447/1330/files/9719643928.pdf
    • https://cdn.shopify.com/s/files/1/0428/0667/3575/files/57604551331.pdf
    • https://cdn.shopify.com/s/files/1/0438/4292/8790/files/43448262663.pdf
    • https://cdn.shopify.com/s/files/1/0436/3013/3406/files/8348545377.pdf
    • https://cdn.shopify.com/s/files/1/0430/8166/2628/files/valobuvulepisiped.pdf
    • https://cdn.shopify.com/s/files/1/0432/6676/9051/files/nejavenozupufivafiromote.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007ce0.bin
688adde41914c7cfe92ae158fdc9d3df6d5472c784871114490abbe0b2cb080c
pdf-font-stream PDF embedded font (sfnt) at offset 0x7CE0 5968 bytes
font_01_sfnt_off00009131.bin
a41efee4d9c1dda4e5458ece6a506a786a2c959e38bef732ca057df7a62c3af7
pdf-font-stream PDF embedded font (sfnt) at offset 0x9131 13188 bytes
font_02_sfnt_off0000bab3.bin
1621a87b6bc266bc0e3d5871723ec36fa76dd6d2c9fb76f212020cc469043148
pdf-font-stream PDF embedded font (sfnt) at offset 0xBAB3 16076 bytes