Malicious PDF — malware analysis report

Static analysis result for SHA-256 ecd63000cb1cdc36…

MALICIOUS

PDF

40.6 KB Created: 2020-08-10 05:15:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ebe090b13b9d8a589f7dfe6bf0ff9d4d SHA-1: e55c0bd1ce324eaeece5a518682cf2b2a8fabacc SHA-256: ecd63000cb1cdc36cc6d062ec60321cf854e2a112335bab985a0d4f54c492835
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to external PDF files hosted on various domains, including a redirector URL. The ML classifier strongly indicated maliciousness. The document body, though heavily obfuscated, contains text related to 'Adobe acrobat pro dc vs adobe pdf pack' and the malicious redirector URL, suggesting a lure to trick users into clicking on potentially harmful links. The primary malicious IOC is the redirector URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=adobe+acrobat+pro+dc+vs+adobe+pdf+pack
    • http://files.simcoebug.com/uploads/1/3/0/8/130815381/wafenaviv_favosizifuwo_pofejomegine.pdf
    • http://files.stmichaelmonroe.com/uploads/1/3/0/9/130969960/b09186770d.pdf
    • http://files.western-window.com/uploads/1/3/2/6/132682051/jovumubijonu.pdf
    • http://files.clintonpottery.com/uploads/1/3/2/6/132682106/1827197.pdf
    • https://cdn.shopify.com/s/files/1/0440/4648/3606/files/tarigibamutalabofuwixuv.pdf
    • https://cdn.shopify.com/s/files/1/0431/1020/3545/files/91692373405.pdf
    • https://cdn.shopify.com/s/files/1/0433/5819/1768/files/jebifixamanumo.pdf
    • https://cdn.shopify.com/s/files/1/0428/1961/6935/files/olaudah_equiano_book.pdf
    • https://cdn.shopify.com/s/files/1/0436/3301/6982/files/kawugefudewuz.pdf
    • https://cdn.shopify.com/s/files/1/0437/0438/5686/files/26969524455.pdf
    • https://cdn.shopify.com/s/files/1/0440/4091/3046/files/zunetusezumijobaw.pdf
    • https://cdn.shopify.com/s/files/1/0431/0922/0501/files/33914804201.pdf
    • https://cdn.shopify.com/s/files/1/0428/7266/8319/files/gewedopu.pdf
    • https://cdn.shopify.com/s/files/1/0429/9934/9407/files/antropologia_biologica.pdf
    • https://cdn.shopify.com/s/files/1/0436/0064/2211/files/92941904350.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006033.bin
c4700af6108c16b6b8a41848ea5a06e30628f8d8ac6f5df9a282c2a859b1d6c4
pdf-font-stream PDF embedded font (sfnt) at offset 0x6033 5372 bytes
font_01_sfnt_off0000728f.bin
4b58aae3a4f69a02456e79eebf04d6b00513008657e0a8ec50071f0132ba041c
pdf-font-stream PDF embedded font (sfnt) at offset 0x728F 10228 bytes