Malicious PDF — malware analysis report

Static analysis result for SHA-256 c628bc92408b6192…

MALICIOUS

PDF

49.1 KB Created: 2020-09-01 04:37:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c730e6e42db1a69aac6360afb60d30d2 SHA-1: 0d64f06adadc9853bed1d122c84f0cc3151fdcc3 SHA-256: c628bc92408b61929a795be2c450fc7ee200e0f5f5c5ecc296263118920e5c37
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains embedded links that redirect to a malicious URL, identified by the 'PDF_MALICIOUS_REDIRECTOR_LINK' heuristic. The 'ML_NYX_PDF_MALICIOUS' heuristic also flagged the file with high confidence. The document body, though heavily obfuscated, contains a URL that appears to be a lure for printable sheets, suggesting a social engineering tactic. The presence of numerous external PDF links further supports a link farm or redirection strategy.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=cursive+alphabet+printable+sheets
    • https://static.usrfiles.com/ugd/b5aed9_f95c1dcfa7e945c38574823ad622dc4a.pdf
    • https://static.usrfiles.com/ugd/eb5a6a_562bf92441e5438a8aeea1878390df39.pdf
    • https://static.usrfiles.com/ugd/3d0627_bd270cf963d94ab2a1ff9e6767526daa.pdf
    • https://static.usrfiles.com/ugd/b8c837_d2e4ea4c537e4aed807f9165405a8193.pdf
    • https://static.usrfiles.com/ugd/3ceeb9_9ac30412dc43461e9de5c785586b9b61.pdf
    • https://static.usrfiles.com/ugd/eaf48f_fb2e212336484b53b395c71e37e0e811.pdf
    • https://static.usrfiles.com/ugd/b8c837_870f38f1880f485db65ace1972aabca5.pdf
    • https://static.usrfiles.com/ugd/0adedf_6a4fefc9e0ba42c99a2167dd5e2cd84b.pdf
    • https://static.usrfiles.com/ugd/05900a_b43cd6e4c71e480398e1fcb66d837954.pdf
    • https://static.usrfiles.com/ugd/b8c837_acc9de464a35427b99cb71e95afca048.pdf
    • https://static.usrfiles.com/ugd/dc8a8e_4c8ed21ec21248c58640bc8ac31d8479.pdf
    • https://static.usrfiles.com/ugd/fb5067_3f60d0694baf4259810d91eb48949cc3.pdf
    • https://static.usrfiles.com/ugd/b8c837_ec7a96251c714a79ae3c8e2f5075f113.pdf
    • https://static.usrfiles.com/ugd/7c30af_fa93cd3e8b7043588e228b9cba18ab36.pdf
    • https://static.usrfiles.com/ugd/c345b0_cc6a8811aeff415ab2b56428c0677302.pdf
    • https://static.usrfiles.com/ugd/b8c837_a86d8827fcc54690a3be15e679b07105.pdf
    • https://static.usrfiles.com/ugd/eda9ba_e7839a9aa5924d3b940f3dea38735396.pdf
    • https://static.usrfiles.com/ugd/b8c837_eb7b9ff53afe4665843893c2008d0bbc.pdf
    • https://static.usrfiles.com/ugd/9e53d4_92d59219d9544948a28c6e4157f5cb48.pdf
    • https://static.usrfiles.com/ugd/29c71c_d3fd645ccc8a43a89cf75f65c6502506.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008237.bin
8f8b90a402ac0b10ea3e6c381389fd15076f6237dee7daae1a33a769e09b151d
pdf-font-stream PDF embedded font (sfnt) at offset 0x8237 5012 bytes
font_01_sfnt_off00009335.bin
9b4e9e0106f85b6fcaa3e6cf2e8971e2b449f698dad506f316737da40e574a8e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9335 10452 bytes