Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc0d8cc862759a72…

MALICIOUS

PDF

43.2 KB Created: 2020-08-19 02:14:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e5b84ae036b74d975279c5ae92a06d45 SHA-1: e3a39e488b32a0da9feebda53d0b51d341564a0b SHA-256: dc0d8cc862759a7279bfa4e46de0be23b111f4d5d93ae158c97a71474838df8f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a mass of external links, many of which are SEO-optimized to appear as legitimate downloads. One prominent link, 'https://ttraff.cc/pify?keyword=organizational+chart+template+for+powerpoint+2010', redirects to malicious infrastructure. The ML classifier strongly indicated maliciousness, and the PDF structure suggests a link farm designed to lure users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=organizational+chart+template+for+powerpoint+2010
    • http://files.jojoamo.com/uploads/1/3/0/8/130874514/zugosadanejasu_japal_rokuxarukitum_gifevudate.pdf
    • http://files.wildandscenicnashuarivers.org/uploads/1/3/0/8/130813616/negawizatowuwot_mivozexojezo.pdf
    • http://jijad.nursegonestrong.com/uploads/1/3/1/6/131636665/wefenina-buxisowunafijop.pdf
    • http://files.nikkieartistry.com/uploads/1/3/0/8/130874110/jevikazevup_vuwizefutip_gagexixalufep.pdf
    • http://files.kamafittv.com/uploads/1/3/1/3/131384604/selivi.pdf
    • https://cdn.shopify.com/s/files/1/0429/9302/5187/files/vabuxefozodararu.pdf
    • https://cdn.shopify.com/s/files/1/0440/1915/5109/files/quran_malayalam.pdf
    • https://cdn.shopify.com/s/files/1/0438/0894/8386/files/descargar_libros_para_aprender_frances_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0437/1536/2984/files/metodo_de_ovulacion_billings.pdf
    • https://cdn.shopify.com/s/files/1/0429/6084/7004/files/92275794777.pdf
    • https://cdn.shopify.com/s/files/1/0428/1873/2191/files/95945221804.pdf
    • https://cdn.shopify.com/s/files/1/0431/7616/5536/files/administering_a_sql_database_infrastructure_2020.pdf
    • https://cdn.shopify.com/s/files/1/0437/6081/2189/files/842318731.pdf
    • https://cdn.shopify.com/s/files/1/0429/9682/6261/files/19286335638.pdf
    • https://cdn.shopify.com/s/files/1/0430/8559/4775/files/19115747290.pdf
    • https://cdn.shopify.com/s/files/1/0433/4111/9647/files/paxojimadumajumabopobesa.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/koxumugude.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000069ac.bin
5f3b45ddb6572ca5116b79c9acd5b990a6e347d8089bbc7d1a78dcad1787a752
pdf-font-stream PDF embedded font (sfnt) at offset 0x69AC 5748 bytes
font_01_sfnt_off00007d31.bin
9195b2f66e7f7eaddd362cb630a30d35a64c698d2f366e36cbe61ee02b07791d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D31 9800 bytes