Malicious PDF — malware analysis report

Static analysis result for SHA-256 ecb1d45417e7a69f…

MALICIOUS

PDF

47.9 KB Created: 2020-08-19 04:49:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ee2f380ff3e947d2c1b86c3b1c9e1ff0 SHA-1: bb95f2f7788634272d36385a8b40487c60a19a0f SHA-256: ecb1d45417e7a69f34062988502bc0aae5e00888e1b9e3a9d4a985f8c6a4cf32
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, indicating an attempt to lead the user to a harmful site. The document body, though heavily obfuscated, contains the same URL, reinforcing the malicious intent. The ML classifier also strongly flagged this PDF as malicious. The primary attack pattern involves luring the user via a link disguised as relevant content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=performance+bottlenecks+in+informatica
    • http://files.learningwithdigitaltechnologies.com/uploads/1/3/1/4/131438211/lofube-pupufasinuxowos-zezeleninov-muvapote.pdf
    • http://vineroge.apeacefulfarewell.com/uploads/1/3/1/3/131378780/darejawamuzigawu.pdf
    • http://files.veinclinicmb.com/uploads/1/3/0/9/130969577/daranonoxaz.pdf
    • http://files.freshtouchph.com/uploads/1/3/0/8/130874522/2252931.pdf
    • http://vineroge.apeacef
    • https://cdn.shopify.com/s/files/1/0437/4790/1592/files/88049436525.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/10542261424.pdf
    • https://cdn.shopify.com/s/files/1/0440/8757/4678/files/12903850649.pdf
    • https://cdn.shopify.com/s/files/1/0439/4598/4158/files/liquidez_bancaria.pdf
    • https://cdn.shopify.com/s/files/1/0431/6043/6887/files/bonemunaxo.pdf
    • https://cdn.shopify.com/s/files/1/0432/3724/5086/files/7107884145.pdf
    • https://cdn.shopify.com/s/files/1/0433/2571/8678/files/zagerutokiralosisabexilut.pdf
    • https://cdn.shopify.com/s/files/1/0434/0160/9366/files/zexolamiki.pdf
    • https://cdn.shopify.com/s/files/1/0437/6988/8920/files/zuxigijodubumiroked.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007e36.bin
b6f208e58c7d6cb06443fd523b37ed05a22a0582e297f88a1922f3e5c93aa7b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E36 5232 bytes
font_01_sfnt_off00008fe7.bin
6429ff83142d79374fb7fa8652c634fc3123ce8034f9bf81d4a157d09a29c850
pdf-font-stream PDF embedded font (sfnt) at offset 0x8FE7 10124 bytes