Malicious PDF — malware analysis report

Static analysis result for SHA-256 0414ad3ff3383d5c…

MALICIOUS

PDF

130.9 KB Created: 2020-09-01 11:08:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 05a3b5f8552b9db6716b3de75f7cdb34 SHA-1: d7a723d62e79761ae89a64015adae9a8c35f3167 SHA-256: 0414ad3ff3383d5c16eabeb138d1d5b51f742c3194e79fa1b4fd7bb1748346b0
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file contains numerous links, with one identified as a malicious redirector. The document body, though heavily obfuscated, contains a URL that matches the malicious redirector. The ML classifier strongly flagged this PDF as malicious, and the presence of a link farm suggests an attempt to distribute malicious content or engage in SEO manipulation for malicious purposes. The primary IOC is the identified malicious redirector URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=android+17+and+18+tournament+of+power
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/15ebe2_31eb0c1934fe43a78efd144961b63fb4.pdf
    • https://static.usrfiles.com/ugd/b8c837_9624d14830c74476a1917027b3de8b7f.pdf
    • https://static.usrfiles.com/ugd/2486b5_85648b6cdcac4609956d64b38860435d.pdf
    • https://static.usrfiles.com/ugd/432b07_f338fc16e3fe4fc7abd085e15dae671c.pdf
    • https://static.usrfiles.com/ugd/4b7290_124f5a326c544d71857b430cfb8d8a37.pdf
    • https://static.usrfiles.com/ugd/1ee69b_747525a3bd6e409d94470eaba0a78a3e.pdf
    • https://static.usrfiles.com/ugd/0adedf_4861b821c6874f6dbcdc3b7379b86cb4.pdf
    • https://static.usrfiles.com/ugd/756799_db675891516a4684ad9a33341eabd04f.pdf
    • https://static.usrfiles.com/ugd/111c46_c2e572db09fb4e8ca41616cb72b8271f.pdf
    • https://static.usrfiles.com/ugd/822ecd_2b9b0f61a892486f94646926d14d7cca.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/35209966956.pdf
    • https://cdn.shopify.com/s/files/1/0431/2439/2087/files/fitodu.pdf
    • https://cdn.shopify.com/s/files/1/0433/9925/0072/files/kubijubutepuxexozamaj.pdf
    • https://cdn.shopify.com/s/files/1/0438/8470/7992/files/advanced_editor.pdf
    • https://cdn.shopify.com/s/files/1/0433/7251/1386/files/6_claves_para_aprender_ingls_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0454/7185/8838/files/apologeticum_tertulliano.pdf
    • https://cdn.shopify.com/s/files/1/0440/6041/0006/files/50238491496.pdf
    • https://cdn.shopify.com/s/files/1/0428/9721/1558/files/sinonimo_de_conforme_exposto.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001b2bc.bin
c49b80f2b67c4fd49bf48f000af19ea3482fe734367b8f5820b0a5c24d0b0caf
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B2BC 5664 bytes
font_01_sfnt_off0001c652.bin
7baff6ba42d04140423584a8dfceb631ac2d878975bf7787917d6109407e2b88
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C652 5384 bytes
font_02_sfnt_off0001d8ad.bin
28272d34785d5ce1c9b98223e6fd79c8d70d03725782464c46893bb9f5c88c07
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D8AD 10816 bytes