Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc95979b3d2a02b3…

MALICIOUS

PDF

40.8 KB Created: 2020-08-28 09:24:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0f1d642ddec13ee04ae0eae61a6d877e SHA-1: 7f580d1f64004b82655abe35d31e43a94f3f94df SHA-256: fc95979b3d2a02b3016ce25befb16ccd5144d6e9b20ab0e8ca2f822183fff416
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded links, with a critical heuristic firing for a malicious redirector. The document body, though heavily obfuscated, contains text that appears to be a lure for 'Premo polymer clay color mixing chart'. The primary malicious IOC is the redirector URL, which is likely used to funnel victims to further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=premo+polymer+clay+color+mixing+chart
    • http://mojetusu.lordandandragallery.com/uploads/1/3/0/7/130776886/kalirosonilukubewax.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/jatud.pdf
    • https://cdn.shopify.com/s/files/1/0433/3846/5435/files/el_capitan_vm.pdf
    • https://cdn.shopify.com/s/files/1/0439/5306/2043/files/69011516462.pdf
    • https://cdn.shopify.com/s/files/1/0434/4401/1168/files/dolefuvopesobatojomibin.pdf
    • https://cdn.shopify.com/s/files/1/0431/1249/7312/files/7345936008.pdf
    • https://cdn.shopify.com/s/files/1/0430/8451/3444/files/73067224123.pdf
    • https://cdn.shopify.com/s/files/1/0434/1573/2381/files/anaheim_ducks_schedule.pdf
    • https://cdn.shopify.com/s/files/1/0435/9910/2110/files/12407342439.pdf
    • https://cdn.shopify.com/s/files/1/0434/2179/4460/files/megapiwojazevusobufali.pdf
    • https://cdn.shopify.com/s/files/1/0432/4396/2532/files/25210346862.pdf
    • https://cdn.shopify.com/s/files/1/0431/9110/7752/files/mepunakigotivoru.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000604a.bin
26a5d0c4fbd15e97300d30c76e8233b40610ccd1cf4de30bb2b339f7bbb08cb9
pdf-font-stream PDF embedded font (sfnt) at offset 0x604A 5340 bytes
font_01_sfnt_off00007250.bin
8d1b7fde5d76d5178e4073e5cafda755aa4a69d9c3ccb5e7fe01fdf65869f662
pdf-font-stream PDF embedded font (sfnt) at offset 0x7250 10528 bytes