Malicious PDF — malware analysis report

Static analysis result for SHA-256 f081de1b58a6ef8b…

MALICIOUS

PDF

40.9 KB Created: 2020-09-19 01:36:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dd7fce157ee3a778ab221ce111907907 SHA-1: 1bd80ccf76741da158bd679709381b43549c69e4 SHA-256: f081de1b58a6ef8b0cd670857b5293b68924d19c5c7c6e7a1517f29379df52f8
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link, which is also present in the document body. This link, disguised as a 'Dead space 3 crafting guide', likely leads to a malicious site. The presence of numerous other PDF links, many pointing to similar URL structures, suggests a link farm or a method to obscure the final destination. The ML classifier strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=dead+space+3+crafting+guide
    • http://files.malibusocceracademy.com/uploads/1/3/2/8/132815207/luwolepitev.pdf
    • http://lekak.hilltoppertennis.com/uploads/1/3/1/1/131164394/luzudimujikuwo.pdf
    • http://files.kg-games.com/uploads/1/3/1/6/131607010/2714245.pdf
    • http://xivovum.triplecrownlacrosse.com/uploads/1/3/1/4/131453558/detax.pdf
    • https://cdn.shopify.com/s/files/1/0433/7877/0076/files/78898652969.pdf
    • https://cdn.shopify.com/s/files/1/0437/2260/4695/files/iap_immunization_schedule_2020_download.pdf
    • https://d32bd628-ee14-469a-aa40-4fbb7f78e665.filesusr.com/ugd/e745be_1d58b85717814b19a4102a71fae0cb09.pdf?index=true
    • https://bef972a2-7976-4724-98e7-190343bd6328.filesusr.com/ugd/a2c2bc_e8d52bc8c29d4163a4867df21ec57cef.pdf?index=true
    • https://6eeb2bac-72db-4158-84ad-27870fa0d91a.filesusr.com/ugd/d94ae5_cd3bc24547b14d1da30b05134f609b48.pdf?index=true
    • https://1aceafe3-9b90-4998-a388-e0455de4239a.filesusr.com/ugd/d48fe3_cd4d3e02e7fe465390670f5169492d2e.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0430/3778/6266/files/ziredivixejaniborotufopez.pdf
    • https://cdn.shopify.com/s/files/1/0428/3056/1447/files/osrs_fletching_profit.pdf
    • https://cdn.shopify.com/s/files/1/0431/7492/0347/files/tatunu.pdf
    • https://cdn.shopify.com/s/files/1/0431/5355/5607/files/71539102007.pdf
    • https://cdn.shopify.com/s/files/1/0430/3329/7058/files/credit_suisse_global_wealth_report_2010.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005dcd.bin
a7d3d7050ffee3c78b63accef9a5564deeff7fca8951ea8216204c750c949a1e
pdf-font-stream PDF embedded font (sfnt) at offset 0x5DCD 5452 bytes
font_01_sfnt_off00007070.bin
ea829fa4f2f7fb9fae8f963d2f83fac28ecc844c86ffa19b79eb4292233ba53e
pdf-font-stream PDF embedded font (sfnt) at offset 0x7070 11864 bytes