Malicious PDF — malware analysis report

Static analysis result for SHA-256 ebf2b8d6fe076ff0…

MALICIOUS

PDF

76.0 KB Created: 2020-09-19 03:59:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f46f255dcbf219be61b6af53ac298606 SHA-1: 2031959bc9c51c86697e6a077db50eb1cbeefa98 SHA-256: ebf2b8d6fe076ff017e89899053f4069979da47cdfae52487b3893346bdb8fd0
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous embedded links, with one specifically pointing to a known malicious redirector. The document body, though partially corrupted, contains text related to 'Ocean state job lot' and the malicious URL, suggesting a lure to trick users into clicking the malicious link. The presence of a link farm heuristic further indicates a malicious intent to distribute malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=ocean+state+job+lot+portsmouth+avenue+stratham+nh
    • https://cdn.shopify.com/s/files/1/0464/6374/6200/files/canine_abdominal_ultrasound_report_template.pdf
    • https://cdn.shopify.com/s/files/1/0428/9367/2604/files/ccna_security_book_2020.pdf
    • https://cdn.shopify.com/s/files/1/0431/9015/7474/files/13971860002.pdf
    • https://ac67b278-e285-4e4a-a996-a5f58a36d817.filesusr.com/ugd/fd4c29_b41d607eabde4146b0a54a2e68decf04.pdf?index=true
    • https://9752b4e5-786e-46b8-9f3e-795087291038.filesusr.com/ugd/9734e7_46fa322305db43c6ba677db5689c044a.pdf?index=true
    • https://af72274c-8db1-4b9e-82dc-879cc9b8b28c.filesusr.com/ugd/7a359d_c608db462c93414380f454b9ef4d7fdf.pdf?index=true
    • https://1da92464-f141-45df-ada1-895977d38edf.filesusr.com/ugd/3eed2b_eb369cfa780e4470bc7306448b16bf8f.pdf?index=true
    • https://9cc17314-2340-4728-9942-4db895cd3cec.filesusr.com/ugd/f34323_cd5105312d2c4c049d58a6a32421112a.pdf?index=true
    • https://40fdd5c6-6522-44d2-9c06-3a1e08bc5d04.filesusr.com/ugd/69695d_3fd8cd687e2245d1b3ddab620c813dc4.pdf?index=true
    • https://9cda30a1-fd17-41bd-8398-35825f4ed8fe.filesusr.com/ugd/ab63e3_77b5e88e6b13426381d3b7e99f052ddf.pdf?index=true
    • https://0a73e7d4-ea03-4350-b993-ed4918b48382.filesusr.com/ugd/760101_7872d35594ae415ca6bd042ab5a33c6e.pdf?index=true
    • https://cf9f6b95-a637-4d51-a091-db2ee2c9748f.filesusr.com/ugd/d01287_b9472f210b0c4900a752b67a9658dd86.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0434/5154/7800/files/36647153086.pdf
    • https://cdn.shopify.com/s/files/1/0433/4541/2261/files/6512695304.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d5d9.bin
40f6e6661752c8979dd9c24578247e312b1f8a96592ea74e4fe801b63ddda671
pdf-font-stream PDF embedded font (sfnt) at offset 0xD5D9 5308 bytes
font_01_sfnt_off0000e7c2.bin
75b42974a8030ada0a8ff6fac17aed0d71bb0235522d40ee69bccfe37b3895ff
pdf-font-stream PDF embedded font (sfnt) at offset 0xE7C2 14236 bytes
font_02_sfnt_off000114bd.bin
7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0x114BD 4324 bytes