Malicious PDF — malware analysis report

Static analysis result for SHA-256 007faff4d8ab997b…

MALICIOUS

PDF

48.7 KB Created: 2020-08-30 14:53:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8226121367d7b9bbcb4bd14d23b15ff7 SHA-1: e8820bc3eb3833294c1bffed4c4b1dbd113818c9 SHA-256: 007faff4d8ab997b21967d3810e6bc324f9b18fe593a67d538fde734aae77816
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious Link

The PDF contains a mass external link farm, with one URL pointing to known malicious redirector infrastructure. The document body and embedded links suggest an attempt to lure users to external sites, potentially for further exploitation or phishing. While many links point to benign Shopify-hosted files, the presence of a malicious redirector is a critical indicator.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=latisse+dark+skin
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0459/9175/5938/files/bomgar_jump_client_windows_10.pdf
    • https://cdn.shopify.com/s/files/1/0441/2683/0744/files/ftp_for_3ds.pdf
    • https://cdn.shopify.com/s/files/1/0434/7287/9782/files/bakteri_bacillus_cereus.pdf
    • https://cdn.shopify.com/s/files/1/0433/2303/1720/files/lubujamodudipegum.pdf
    • https://cdn.shopify.com/s/files/1/0441/3099/2280/files/zomataxefofudusizowa.pdf
    • https://cdn.shopify.com/s/files/1/0432/4386/4224/files/cr_250_movesa_especificaes.pdf
    • https://static.usrfiles.com/ugd/d99ef3_ab6d8a2985da41c0a1bcf6f09ee6e505.pdf
    • https://static.usrfiles.com/ugd/b8c837_be5457d0f07345329b450ef9715aedde.pdf
    • https://static.usrfiles.com/ugd/79cb75_a6cc09a5deb34fbcada57cf41e7b9d30.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/mijafovaginidobu.pdf
    • https://cdn.shopify.com/s/files/1/0432/5687/3128/files/pukinamupipidilanud.pdf
    • https://cdn.shopify.com/s/files/1/0437/1808/2709/files/4038959231.pdf
    • https://cdn.shopify.com/s/files/1/0429/5432/6179/files/13299493113.pdf
    • https://cdn.shopify.com/s/files/1/0460/0253/6607/files/barnes_match_burner_load_data.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000069ce.bin
77d7ca5a2c0469e71498019454eb47d4ab29b8866212e45f70dde710f4d5790c
pdf-font-stream PDF embedded font (sfnt) at offset 0x69CE 4472 bytes
font_01_sfnt_off000078ed.bin
6d2a3a16cc464ce72cf05976c7f96a31c93af2202e0dc760c37a694345e222ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x78ED 1800 bytes
font_02_sfnt_off0000817d.bin
79a237843e728269840505f061ad8ca3086d32f34de6a388fc8d026e959cb1d8
pdf-font-stream PDF embedded font (sfnt) at offset 0x817D 11308 bytes
font_03_sfnt_off0000a722.bin
ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230
pdf-font-stream PDF embedded font (sfnt) at offset 0xA722 4324 bytes