Malicious PDF — malware analysis report

Static analysis result for SHA-256 c95c11a2ba4f8971…

MALICIOUS

PDF

61.7 KB Created: 2020-08-12 02:56:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9e768ce579f977c13cb5b92f9ec6c493 SHA-1: 3c32d5213a705c99238cc9e21377a94e6005e16f SHA-256: c95c11a2ba4f89715d028e96e3e259c4af49278cd6019a43c47b0592acd2c3e9
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to a redirector service. The document body, though heavily obfuscated, contains text related to a 'Honda Africa Twin manual' and a URL that appears to be a malicious redirector. This suggests a phishing or scam attempt where the user is lured to a malicious site under the guise of downloading a manual. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=honda+africa+twin+2020+manual+pdf
    • http://xelepisuz.stephaniewestliterature.com/uploads/1/3/0/7/130738524/subaresepow.pdf
    • http://kalapef.crackingthehungerartist.com/uploads/1/3/0/8/130814328/foraxaginije.pdf
    • http://files.ngssicons.com/uploads/1/3/0/8/130873728/2121745.pdf
    • https://cdn.shopify.com/s/files/1/0430/3293/6605/files/convert_html_to_in_c_net_free_dll.pdf
    • https://cdn.shopify.com/s/files/1/0429/7375/7603/files/wamifozogixudazipila.pdf
    • https://cdn.shopify.com/s/files/1/0428/9308/2783/files/change_origin_name.pdf
    • https://cdn.shopify.com/s/files/1/0434/6983/2354/files/pijadewatizotumor.pdf
    • https://cdn.shopify.com/s/files/1/0433/0301/0459/files/english_for_business_communication_student_s_book_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0430/2897/1674/files/7750810693.pdf
    • https://cdn.shopify.com/s/files/1/0431/8108/0738/files/4161065511.pdf
    • https://cdn.shopify.com/s/files/1/0429/4069/4684/files/63267127544.pdf
    • https://cdn.shopify.com/s/files/1/0428/9118/2243/files/55375439947.pdf
    • https://cdn.shopify.com/s/files/1/0429/0691/0876/files/cellular_and_humoral_immunity.pdf
    • https://cdn.shopify.com/s/files/1/0432/7089/7824/files/8472556066.pdf
    • https://cdn.shopify.com/s/files/1/0431/8606/1480/files/9402988888.pdf
    • https://cdn.shopify.com/s/files/1/0428/2348/3548/files/64882465525.pdf
    • https://cdn.shopify.com/s/files/1/0430/2897/1681/files/kelijerok.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009b09.bin
415915bc2eb257bf044a66e8fb6bcb70f2e7a0d04a370cd82583a4ef6caebd20
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B09 5212 bytes
font_01_sfnt_off0000acae.bin
9c898d74b08452d7a78596b6b85d75249bf80d670e2b81a20db944794e26eb29
pdf-font-stream PDF embedded font (sfnt) at offset 0xACAE 14896 bytes
font_02_sfnt_off0000db66.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0xDB66 4324 bytes