Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9d19931998f965b…

MALICIOUS

PDF

43.0 KB Created: 2020-09-09 14:57:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 32a8a315a9bef120118ea7c393d4c4cb SHA-1: c6e8da756c286c4a134db9084f6b6d3a08b0dea9 SHA-256: f9d19931998f965b7485de6d9eba4bf54d7435f8904a98b8814380eeef280485
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link disguised as a programming tutorial search result, which redirects to a known malicious domain. The ML classifier strongly indicated maliciousness, and the PDF structure includes a link farm pointing to various benign-looking PDFs, likely to improve search engine ranking for malicious redirects. No scripts were extracted, but the primary attack vector is the malicious redirector link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=learn+basics+of+c+programming+pdf
    • http://files.newcastlemastershockey.org/uploads/1/3/1/4/131483098/3878936.pdf
    • http://files.rlx.space/uploads/1/3/1/4/131409200/4318698.pdf
    • http://files.exmouthcaninecentre.co.uk/uploads/1/3/0/8/130874128/jenasaj.pdf
    • https://cdn.shopify.com/s/files/1/0436/7620/5209/files/clinical_chemistry_bishop.pdf
    • https://cdn.shopify.com/s/files/1/0428/6133/0598/files/carte_des_espaces_agricoles_en_france.pdf
    • https://cdn.shopify.com/s/files/1/0428/8679/1334/files/91157190042.pdf
    • https://static.usrfiles.com/ugd/89363e_a41fd2d7d7624df8a44f578802a1692e.pdf
    • https://static.usrfiles.com/ugd/4cf28d_7139dceed25541f7b0edcd17d1b4b003.pdf
    • https://static.usrfiles.com/ugd/b8c837_023fcff311f84dc89e92900234c5be53.pdf
    • https://static.usrfiles.com/ugd/e78b77_a30c1bd17a034fef945d0173966369e4.pdf
    • https://static.usrfiles.com/ugd/120874_de9995de4ce54b91b7a82f8dd2d1492c.pdf
    • https://static.usrfiles.com/ugd/dad7b5_38ddfcf0c08c407eb5701304e6770d3b.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006937.bin
2bb4a14273ab2a3ee1db3b56c33ca1f6f06e386b9a6f4ee6fa0753c2acd1c5ff
pdf-font-stream PDF embedded font (sfnt) at offset 0x6937 5524 bytes
font_01_sfnt_off00007bf0.bin
1f5ecf3fe68fb735eb22fc15e92264761905bb1eba8ebfcc8a3f075d6c066b76
pdf-font-stream PDF embedded font (sfnt) at offset 0x7BF0 10476 bytes