Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2251011ed413820…

MALICIOUS

PDF

45.8 KB Created: 2020-08-12 23:50:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 34f7a48abd457aae2d156977ca9ff626 SHA-1: a6cd2595380b0330f36322b3b57f94f1bfeb5b9a SHA-256: a2251011ed41382082ae4a457c453b80e596d147ae038f03ba76d3d32ee9dd7a
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a deceptive link disguised as a download for 'engineering science notes pdf download'. This link, identified as a malicious redirector, leads to `https://ttraff.cc/wb?keyword=engineering%20science%20notes%20pdf%20download`. The document also features a large number of external links, many pointing to benign Shopify URLs, suggesting an attempt to manipulate search engine results or create a link farm. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=engineering%20science%20notes%20pdf%20download
    • http://files.siljaviermann.com/uploads/1/3/0/7/130775866/4694753.pdf
    • http://files.californiahydrogenwater.com/uploads/1/3/1/8/131856012/besodagi_galinosizamipud_jedazo_riwaze.pdf
    • http://jewon.murielkneeshaw.com/uploads/1/3/0/9/130969332/6231776.pdf
    • http://kalivuj.shawncorneliusentertainment.com/uploads/1/3/0/8/130873951/mugaxisivilel.pdf
    • https://cdn.shopify.com/s/files/1/0435/7708/2019/files/bread_box_plans.pdf
    • https://cdn.shopify.com/s/files/1/0432/9832/4640/files/adobe_reader_full_setup_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0433/2909/3800/files/aws_sysops_exam_dumps_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0430/9889/8592/files/aafp_guidelines.pdf
    • https://cdn.shopify.com/s/files/1/0438/6874/9979/files/90453142381.pdf
    • https://cdn.shopify.com/s/files/1/0431/0705/7825/files/introduction_to_sociology_and_anthropology_by_palispis.pdf
    • https://cdn.shopify.com/s/files/1/0440/0221/4046/files/graphic_design_thinking.pdf
    • https://cdn.shopify.com/s/files/1/0439/8222/5566/files/19305182832.pdf
    • https://cdn.shopify.com/s/files/1/0440/8170/9206/files/89168192591.pdf
    • https://cdn.shopify.com/s/files/1/0432/6742/4416/files/sununajavaketimegagil.pdf
    • https://cdn.shopify.com/s/files/1/0431/4651/0504/files/clockwork_angel_online.pdf
    • https://cdn.shopify.com/s/files/1/0431/1682/2679/files/12306927011.pdf
    • https://cdn.shopify.com/s/files/1/0429/7926/2615/files/revolucion_epigenetica.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006756.bin
56ef697d4a623d201fa70c3011bbd26a98e38ac93a154c86b2cae45939a0d678
pdf-font-stream PDF embedded font (sfnt) at offset 0x6756 5372 bytes
font_01_sfnt_off000079bf.bin
f492a896882f93209bf4bb3c639f8d6441bceaf82e6c13f424ee3acd98f8d56b
pdf-font-stream PDF embedded font (sfnt) at offset 0x79BF 15016 bytes