Malicious PDF — malware analysis report

Static analysis result for SHA-256 db461c5a835c8635…

MALICIOUS

PDF

45.8 KB Created: 2020-08-15 03:27:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f7387b51862f9790842d26d6dba9a7be SHA-1: 6900af764e411d01fd3ac965f951fa26c255b3ac SHA-256: db461c5a835c86355bfd49bf42bb55b3a43a65c4ca98b2b4e60fe6730da24095
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, which is designed to lure users into downloading potentially harmful content. The document body, though heavily obfuscated, contains text related to 'blackmart app free for iphone' and the malicious URL, suggesting a phishing or scam attempt. The presence of a large number of external PDF links also indicates a link farm, likely for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=blackmart+app+free++for+iphone
    • http://files.nirmalaganganagari.com/uploads/1/3/0/9/130969775/3405845.pdf
    • https://cdn.shopify.com/s/files/1/0434/8346/3832/files/60345092138.pdf
    • https://cdn.shopify.com/s/files/1/0430/1442/2677/files/48861913079.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/56966684837.pdf
    • https://cdn.shopify.com/s/files/1/0437/2067/1386/files/ubuntu_mount_cifs.pdf
    • https://cdn.shopify.com/s/files/1/0448/2249/5389/files/fusionner_plusieurs_en_un_seul_fichier.pdf
    • https://cdn.shopify.com/s/files/1/0439/9028/6494/files/98268730640.pdf
    • https://cdn.shopify.com/s/files/1/0450/3116/2006/files/adjectives_worksheets_grade_2.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/jikoleluvotejagumali.pdf
    • https://cdn.shopify.com/s/files/1/0431/7180/7391/files/mixumiwimofuvibigugujor.pdf
    • https://cdn.shopify.com/s/files/1/0434/2199/1079/files/subsetting_in_r.pdf
    • https://cdn.shopify.com/s/files/1/0429/4747/7667/files/99448796474.pdf
    • https://cdn.shopify.com/s/files/1/0430/2667/7913/files/45682736646.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000075a7.bin
4f8ed6444e1b3657246107597c071e10579a93771ea0903bb3f4390e6c0363a1
pdf-font-stream PDF embedded font (sfnt) at offset 0x75A7 5188 bytes
font_01_sfnt_off00008728.bin
7b6732d721e0f310aacd7b8c88757758cf1e43cba867791909c1299696895b94
pdf-font-stream PDF embedded font (sfnt) at offset 0x8728 10292 bytes