Malicious PDF — malware analysis report

Static analysis result for SHA-256 000db9d10043fded…

MALICIOUS

PDF

45.8 KB Created: 2020-08-31 21:50:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8c13942d6e1adc07621f7e16cb12c736 SHA-1: f2f54f5360239bec4d028ba38e5ee3d2e739fbc4 SHA-256: 000db9d10043fded37aeb58621014e19d134e688c06be2dc45821cc3f4a57334
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a malicious redirector link disguised as a free invite template, aiming to trick users into clicking it. The ML classifier strongly indicates maliciousness, and the document body contains the lure text along with the malicious URL. The PDF also hosts a large number of other links, likely for SEO manipulation or to obscure the primary malicious destination.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=invite+template+free+word
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0430/8320/2711/files/83236965889.pdf
    • https://cdn.shopify.com/s/files/1/0462/4380/7392/files/jatedezudunugofidejipi.pdf
    • https://cdn.shopify.com/s/files/1/0431/6869/4432/files/6085015773.pdf
    • https://cdn.shopify.com/s/files/1/0434/8638/0197/files/probability_sample_questions_with_solutions.pdf
    • https://cdn.shopify.com/s/files/1/0433/5294/8901/files/38454799796.pdf
    • https://cdn.shopify.com/s/files/1/0431/0335/5034/files/xipunidokikafowe.pdf
    • https://cdn.shopify.com/s/files/1/0435/3071/5288/files/fusisi.pdf
    • https://cdn.shopify.com/s/files/1/0440/3917/6342/files/maduruvabawotupifanul.pdf
    • https://cdn.shopify.com/s/files/1/0432/7263/4533/files/tamemivipagixazuxeruzu.pdf
    • https://cdn.shopify.com/s/files/1/0434/5056/4773/files/15676569523.pdf
    • https://cdn.shopify.com/s/files/1/0433/3443/4969/files/xanonetenu.pdf
    • https://cdn.shopify.com/s/files/1/0429/5606/2876/files/dunefo.pdf
    • https://cdn.shopify.com/s/files/1/0437/1755/8426/files/sega_dreamcast_apk_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/7757/4557/files/32364125489.pdf
    • https://cdn.shopify.com/s/files/1/0429/9623/6447/files/velugifogesuvefolipez.pdf
    • https://cdn.shopify.com/s/files/1/0440/9065/4885/files/66863648035.pdf
    • https://cdn.shopify.com/s/files/1/0431/6246/8503/files/jokuvuzarulox.pdf
    • https://cdn.shopify.com/s/files/1/0431/8402/9854/files/abb_flow_meter_installation_guidelines.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000075ad.bin
fa4c27d71052ca611805fd7b5d212b4faa9c785e3e2ed83efad8d7cff01cfa14
pdf-font-stream PDF embedded font (sfnt) at offset 0x75AD 5096 bytes
font_01_sfnt_off00008704.bin
9534ee969a26a5c8f962073204948cb3359f2ffda61d53d27e9c8bdf257f81a1
pdf-font-stream PDF embedded font (sfnt) at offset 0x8704 10292 bytes