Malicious PDF — malware analysis report

Static analysis result for SHA-256 00aaafbd0d29a0b6…

MALICIOUS

PDF

46.1 KB Created: 2020-08-30 23:31:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 759bf2fa51a3c6e63969018487b3317e SHA-1: 91258d182adde12737047c57473fca3ad0c6f447 SHA-256: 00aaafbd0d29a0b6abfcf7d07af3f988df9b6634cf4e80ee3119d569122c4118
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

This PDF file exhibits characteristics of a link farm, embedding numerous external links, with one prominent link pointing to a known malicious redirector. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains the URL that triggers the malicious redirector, suggesting an attempt to lure users to malicious infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=40th+anniversary+star+wars
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://static.usrfiles.com/ugd/e32576_d02c5b0e6bc146daad36b070248a12fd.pdf
    • https://static.usrfiles.com/ugd/cb5dea_c81f98031a8a4225847c85413703bafe.pdf
    • https://static.usrfiles.com/ugd/38bf1f_dbfa1c2b69924079b209989d7feacddf.pdf
    • https://static.usrfiles.com/ugd/625844_18759605c4fa4417bfbf623cd5eb543f.pdf
    • https://static.usrfiles.com/ugd/cafc24_deadce8903fc44d38c04cb976d4be29c.pdf
    • https://static.usrfiles.com/ugd/b8c837_b4e5ea3fad004ec3a29dbe9c4c9eb0f7.pdf
    • https://static.usrfiles.com/ugd/b8c837_ebb3f774907b4a09a52d5f7ee66dbc9a.pdf
    • https://static.usrfiles.com/ugd/b8c837_aad9bfa8932b404c8e8472955442502f.pdf
    • https://static.usrfiles.com/ugd/0c41e7_90c3f1073b9242d9988488c58ba4a046.pdf
    • https://static.usrfiles.com/ugd/22739b_043c8ef7e23a4f4fbff7b36fb792f6d0.pdf
    • https://static.usrfiles.com/ugd/e02969_36c0685445c64f8bb322584cd6ba32e9.pdf
    • https://cdn.shopify.com/s/files/1/0439/6879/0686/files/wojizeleranazurexom.pdf
    • https://cdn.shopify.com/s/files/1/0438/7491/0376/files/97890662856.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b79.bin
bed5a3b5a7bffbf89d2526d0053e861f23c1dbacd53d4054ec4fb793e61b776d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B79 4808 bytes
font_01_sfnt_off00007bc7.bin
b93c136f1307b58332c4be9961bfa200585e66307faedcdcb80fb85163ac10f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x7BC7 9940 bytes
font_02_sfnt_off00009dde.bin
ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230
pdf-font-stream PDF embedded font (sfnt) at offset 0x9DDE 4324 bytes