Malicious PDF — malware analysis report

Static analysis result for SHA-256 c1e72f4cc9f8fa4b…

MALICIOUS

PDF

43.6 KB Created: 2020-08-31 03:23:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f3f0db01433fcc40c2bbf96616b7138c SHA-1: d2df56ad3478ff7d450022014121a7fd7b6fa4b7 SHA-256: c1e72f4cc9f8fa4b7daa846318321e5f6e476c9dd79a3c92efb636081f36bbb9
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains multiple embedded links, with one critical heuristic identifying a link to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains a URL that appears to be the same as the one flagged by the heuristic. The presence of numerous external PDF links, many hosted on Shopify, suggests a link farm or SEO poisoning tactic to distribute malicious content. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=hershel+and+the+hanukkah+goblins+pdf
    • https://cdn.shopify.com/s/files/1/0431/8016/3227/files/16820433224.pdf
    • https://cdn.shopify.com/s/files/1/0431/7511/6959/files/tijimexudojezugi.pdf
    • https://cdn.shopify.com/s/files/1/0437/7087/1970/files/51373259274.pdf
    • https://cdn.shopify.com/s/files/1/0430/6114/9850/files/restaurar_backup_whatsapp_android_no_iphone.pdf
    • https://cdn.shopify.com/s/files/1/0432/5507/0880/files/rebivi.pdf
    • https://static.usrfiles.com/ugd/2813e2_c701a1bb7d7c47eb9e07d4f446810ca8.pdf
    • https://static.usrfiles.com/ugd/c7ef1a_464cefc6da28470b94d865d104c4f6d8.pdf
    • https://cdn.shopify.com/s/files/1/0436/8351/2473/files/carcinoma_basocelular_fisiopatologia.pdf
    • https://cdn.shopify.com/s/files/1/0433/9371/2286/files/45263795183.pdf
    • https://cdn.shopify.com/s/files/1/0429/8738/9087/files/vizafe.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/digalikerewuxajevukadud.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000057a4.bin
2a0677dfd290cac92cc25a9161f6e1bc386543080cabb69d9f4ecc2cc93f860d
pdf-font-stream PDF embedded font (sfnt) at offset 0x57A4 5468 bytes
font_01_sfnt_off00006a28.bin
a7fc7cacf1be786a5d3ea30ed8d639d6912c7db9f182b18e2a2be79203d3d3fe
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A28 10032 bytes
font_02_sfnt_off00008cb5.bin
9af6fc3bf9d751f70540aea0fa47faa159a3604992cda23d2adcda3ffc5346b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CB5 16092 bytes