Malicious PDF — malware analysis report

Static analysis result for SHA-256 cf4fef728bd2460c…

MALICIOUS

PDF

45.8 KB Created: 2020-09-16 16:20:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d7376e122f6fddc3bb5c9e85646b4ca9 SHA-1: 05dc8c6e1ea38f9506657f7a7a8a4db6799cef8b SHA-256: cf4fef728bd2460c74bb8b96d3e2abde896e94725a0283d59d71ef1df0ebee15
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous links, with a critical heuristic identifying a link to a known malicious redirector infrastructure. The document body, though heavily obfuscated, contains the same URL found in the heuristic. The presence of many external PDF links suggests a link farm or SEO poisoning tactic to distribute malicious content. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=bully+penelope+douglas+pdf+espa%25C3%25B1ol
    • http://files.rewindind.com/uploads/1/3/1/4/131438639/majab.pdf
    • http://files.mcandrewhealthlab.com/uploads/1/3/2/6/132695576/7122db55.pdf
    • http://files.12southcarriagehouse.com/uploads/1/3/0/7/130739202/matoziruv-diduwexojubalox.pdf
    • https://cdn.shopify.com/s/files/1/0432/9524/4441/files/bosejadajug.pdf
    • https://cdn.shopify.com/s/files/1/0427/9074/8316/files/dearly_beloved_violin_solo_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0439/4817/9611/files/samefuwar.pdf
    • https://cdn.shopify.com/s/files/1/0433/6238/6079/files/tabla_de_derivadas_completa.pdf
    • https://cdn.shopify.com/s/files/1/0430/2651/4077/files/rilejopo.pdf
    • https://ce1c8256-c882-471b-b93f-87b86c490f90.filesusr.com/ugd/0a0016_24f765b582d24e6e8ee90b3d12d31624.pdf?index=true
    • https://4f03cdfc-6f44-4d80-addc-c7144d70b4ce.filesusr.com/ugd/d3758e_4d7dc3a330df46dbb21e6bd4c243e08c.pdf?index=true
    • https://6ba83510-2db4-480e-84e6-84dc02dd614c.filesusr.com/ugd/07e02c_220f0073ed2b41b0ac2d60a7f7c6922a.pdf?index=true
    • https://fa5ac6a6-68c7-4882-a980-bc3f2eced65e.filesusr.com/ugd/135178_09570144b6d04d6a9b461184f078474b.pdf?index=true
    • https://1f10a773-02fa-4949-88dc-da9b20055c27.filesusr.com/ugd/fb5067_f201620879db49b3b3c05fd23c67ed01.pdf?index=true
    • https://499e80fb-d343-471d-a230-68d39b487374.filesusr.com/ugd/dc8a8e_079609dd166d4eb99a397fb5155e6802.pdf?index=true
    • https://33403046-6fe3-458a-a672-6cfe2b6b5298.filesusr.com/ugd/07e02c_37490d8ea8ec49b18008e88de9137a37.pdf?index=true
    • https://0cb6ae8e-cd15-46ef-b0bf-37c21e26a033.filesusr.com/ugd/3e87bf_500519e43e3541d588be5f58032132fd.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://0cb6ae8e-cd15-46ef-b0bf-37c21e26a033.filesusr.com/ugd/3e87bf_500519e43e3541d588

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000071a2.bin
ebd220937bd1cfc71af3568e082a392170d7b7422a47b2fd1e545ed8a8a1a136
pdf-font-stream PDF embedded font (sfnt) at offset 0x71A2 5476 bytes
font_01_sfnt_off0000842d.bin
e042f9c5a355a55bd51388952acb904a4c392ab4b9b82cec30acc486c2836023
pdf-font-stream PDF embedded font (sfnt) at offset 0x842D 10648 bytes