Malicious PDF — malware analysis report

Static analysis result for SHA-256 e6b92799535b0221…

MALICIOUS

PDF

40.2 KB Created: 2020-08-14 17:52:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 34095b93f2a5d2e76d8f841ec66541d7 SHA-1: bbc7109d125d7f1497711198985030ee52b68032 SHA-256: e6b92799535b0221819db4178fd3f9ad20e97ab9a7e2623b331a4b2b5670e8ab
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains embedded links, one of which points to a known malicious redirector. The document body, though heavily obfuscated, contains text related to 'pressure vessel cost estimation spreadsheet' and the malicious URL. This suggests a phishing or social engineering attack aiming to redirect the user to malicious infrastructure. The presence of numerous other Shopify links, while benign, is characteristic of SEO spam techniques used to mask malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=pressure+vessel+cost+estimation+spreadsheet
    • http://files.afmsupplements.com/uploads/1/3/2/3/132302815/972851.pdf
    • http://pijamitu.bestsyntheticstore.com/uploads/1/3/0/7/130776677/1334278.pdf
    • https://cdn.shopify.com/s/files/1/0431/1564/3042/files/10480621799.pdf
    • https://cdn.shopify.com/s/files/1/0431/6751/4788/files/fodulijumakufurojanikol.pdf
    • https://cdn.shopify.com/s/files/1/0435/6934/8763/files/accelerated_c_koenig_moo.pdf
    • https://cdn.shopify.com/s/files/1/0440/2610/1925/files/donation_receipt_template_canada.pdf
    • https://cdn.shopify.com/s/files/1/0432/3459/0888/files/30852940675.pdf
    • https://cdn.shopify.com/s/files/1/0431/7567/4024/files/lok_sabha_election_2020_results_state_wise.pdf
    • https://cdn.shopify.com/s/files/1/0435/8645/3663/files/properties_of_admixtures.pdf
    • https://cdn.shopify.com/s/files/1/0429/6795/7658/files/zodijexedoro.pdf
    • https://cdn.shopify.com/s/files/1/0439/7550/8126/files/converter_to_word_online_full.pdf
    • https://cdn.shopify.com/s/files/1/0428/2312/3100/files/62729434901.pdf
    • https://cdn.shopify.com/s/files/1/0429/1526/6713/files/zotelibotixu.pdf
    • https://cdn.shopify.com/s/files/1/0431/0761/4882/files/xusuvuvubinirukukezojoz.pdf
    • https://cdn.shopify.com/s/files/1/0430/0649/2831/files/advertising_creative_strategy_copy_and_design_4th_edition.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000051c2.bin
71dfcedddd6dca67c5a4363feccf7167d3ae972506d392ed06afc8b65f639172
pdf-font-stream PDF embedded font (sfnt) at offset 0x51C2 2868 bytes
font_01_sfnt_off00005bf3.bin
d2f79a7091653456bafc19c6553b4f69bc52a84786e809cbef37e71032c4f3fc
pdf-font-stream PDF embedded font (sfnt) at offset 0x5BF3 5376 bytes
font_02_sfnt_off00006e0a.bin
15dcea1ff3290c22abb082b069b612a5a444be8c84cf10cc77754a1ef91978f6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E0A 10356 bytes