Malicious PDF — malware analysis report

Static analysis result for SHA-256 a45a8a66f752bcf2…

MALICIOUS

PDF

69.4 KB Created: 2020-07-31 07:29:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0d7bd5ca3618fc03ece216f0f3b00086 SHA-1: 524d16d01e3fac586bd35ea910ccc7ab3a622d14 SHA-256: a45a8a66f752bcf2049bf94474b00c7809bc7cbb10503a059c3eabd6bf4f0d1b
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF contains multiple embedded URLs, with one specifically identified as a malicious redirector. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' indicates a direct link to malicious infrastructure. Additionally, 'PDF_SEO_LINK_FARM' suggests a large number of links, many hosted on Shopify, likely to obscure the malicious destination. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains text related to 'book pdf download', suggesting a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=be+here+now+book+pdf+download
    • http://files.hopelutherancr.org/uploads/1/3/1/4/131438439/3574207.pdf
    • http://files.turnsofphrase.com/uploads/1/3/1/0/131070678/0d24ced56.pdf
    • http://files.gunitsponsorbootcamp.com/uploads/1/3/1/3/131380397/ca0c24.pdf
    • https://cdn.shopify.com/s/files/1/0440/4789/2630/files/nipoxul.pdf
    • https://cdn.shopify.com/s/files/1/0433/1870/6331/files/84501120740.pdf
    • https://cdn.shopify.com/s/files/1/0440/6371/9574/files/gogumevile.pdf
    • https://cdn.shopify.com/s/files/1/0432/8115/4198/files/gezugasaf.pdf
    • https://cdn.shopify.com/s/files/1/0429/5586/6263/files/munobirejoj.pdf
    • https://cdn.shopify.com/s/files/1/0440/6624/2710/files/zalofilibalotovezegasup.pdf
    • https://cdn.shopify.com/s/files/1/0434/5764/2648/files/dugowanodinikif.pdf
    • https://cdn.shopify.com/s/files/1/0431/2553/8980/files/tuzujanolufujekurevezuwu.pdf
    • https://cdn.shopify.com/s/files/1/0433/7637/8014/files/1324487941.pdf
    • https://cdn.shopify.com/s/files/1/0430/9919/3501/files/bajureretupoxulo.pdf
    • https://cdn.shopify.com/s/files/1/0433/0133/9304/files/29539968905.pdf
    • https://cdn.shopify.com/s/files/1/0435/5653/6471/files/29792650285.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c1ba.bin
b27c7a011d1e25a8740c16753f32df49003034e6b6973e84691b1598814ca5e7
pdf-font-stream PDF embedded font (sfnt) at offset 0xC1BA 6548 bytes
font_01_sfnt_off0000d210.bin
2ccd48efbe6ed058fe44e57badc986a23b88cd7143cb4cf455fa9b7578cc1707
pdf-font-stream PDF embedded font (sfnt) at offset 0xD210 4956 bytes
font_02_sfnt_off0000e2e2.bin
251329c51c99ef1cc6ed1e279efe810c49457d8b86f03651a10ff310db151287
pdf-font-stream PDF embedded font (sfnt) at offset 0xE2E2 10392 bytes