Malicious PDF — malware analysis report

Static analysis result for SHA-256 043443a991de80c0…

MALICIOUS

PDF

49.7 KB Created: 2020-08-24 13:11:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 83ea9926c416455a63dbc3c17292d884 SHA-1: 5a8891640623daa1a5f52331ff5f85c5a73a962b SHA-256: 043443a991de80c0e132634552190d175127872405da9d7a4823fb151bb54ed4
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with one identified as a malicious redirector pointing to 'https://ttraff.com/pify?keyword=axiomatic+method+pdf'. The heuristic 'SE_LOLBIN_RUN_COMMAND' also indicates the presence of commands related to PowerShell within the document text, suggesting an attempt to execute malicious code or download further payloads. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=axiomatic+method+pdf
    • http://files.msgfpa.org/uploads/1/3/1/6/131606165/37e37.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0434/9073/8328/files/aluminum_oxide_properties.pdf
    • https://cdn.shopify.com/s/files/1/0433/7437/9157/files/back_end_developer_interview_questions_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0436/0686/8131/files/3446051306.pdf
    • https://cdn.shopify.com/s/files/1/0432/3049/4878/files/wisutunerepipometazoveduv.pdf
    • https://cdn.shopify.com/s/files/1/0431/6332/0469/files/idioms_worksheets_5th_grade_free.pdf
    • https://cdn.shopify.com/s/files/1/0428/8725/0087/files/self_elevating_powershell_script.pdf
    • https://cdn.shopify.com/s/files/1/0435/3287/7975/files/exam_master_free.pdf
    • https://cdn.shopify.com/s/files/1/0434/3513/1046/files/ropimiron.pdf
    • https://cdn.shopify.com/s/files/1/0434/8408/6424/files/ludav.pdf
    • https://cdn.shopify.com/s/files/1/0430/9634/2695/files/ladajomupesasafasuva.pdf
    • https://cdn.shopify.com/s/files/1/0429/2080/4518/files/armed_heist_apk.pdf
    • https://cdn.shopify.com/s/files/1/0432/6395/1003/files/mapufubumudalezalowapip.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0435
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006428.bin
397f54dee892933d7e9d195000d73fde225450f877fa4e3ef906fd15d31a6e68
pdf-font-stream PDF embedded font (sfnt) at offset 0x6428 4828 bytes
font_01_sfnt_off0000749b.bin
5dc67c26d84d7423e8b03e0250b0b335ef4c52ccd714262cea6fdaf60d3b1b70
pdf-font-stream PDF embedded font (sfnt) at offset 0x749B 10000 bytes
font_02_sfnt_off000096f5.bin
242fba77d96c5ab84cd920abdfd8b8278d36c96caf737e409af15d8068860fd9
pdf-font-stream PDF embedded font (sfnt) at offset 0x96F5 16132 bytes
font_03_sfnt_off0000abe8.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0xABE8 4324 bytes