Malicious PDF — malware analysis report

Static analysis result for SHA-256 077005c21a35a498…

MALICIOUS

PDF

42.0 KB Created: 2020-09-19 14:25:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0005aee4b7616c26fb7e6e2b3dac2317 SHA-1: dc3ea5f948c19a12003451eb499748964c2a5d51 SHA-256: 077005c21a35a498e696a0eaf6d41fcfab33d5711762dd47c99737f5f4761176
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to redirector infrastructure. One prominent link, 'https://ttraff.me/wix?keyword=evo+vr+pro+controller+manual', is identified as malicious. The document body, though heavily obfuscated, appears to contain references to product manuals and URLs, suggesting a lure to trick users into clicking the malicious link. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=evo+vr+pro+controller+manual
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://706a6464-0250-4c58-a882-6202295ddd9d.filesusr.com/ugd/61567a_4fe4728e49654dd397754d9770c31412.pdf?index=true
    • https://60a5a54b-7e46-451e-99fc-13bff7cdd5e9.filesusr.com/ugd/cbe7f7_d5b6d1fed6294e33909d10e2932c475f.pdf?index=true
    • https://ac733151-e26a-421e-8c16-faf5584a5201.filesusr.com/ugd/b52961_c6aa64f4887d43e9bde09f8f2d7d5af3.pdf?index=true
    • https://1f6165b8-8a8d-4a74-85db-e5b393aa12a7.filesusr.com/ugd/9d66c7_ad59a1a09f1643febe7d955a31c3eba9.pdf?index=true
    • https://35a0e9a2-0338-4675-87dc-725fc71a3bed.filesusr.com/ugd/b58d21_dff23fcefd364dc496e87b10e4fa62f4.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0433/3921/9099/files/mozivabalowefajetobil.pdf
    • https://cdn.shopify.com/s/files/1/0432/0677/0843/files/3344959722.pdf
    • https://cdn.shopify.com/s/files/1/0434/2956/0486/files/38910029299.pdf
    • https://cdn.shopify.com/s/files/1/0429/9007/6057/files/psd_to_convertio.pdf
    • https://cdn.shopify.com/s/files/1/0432/4704/2728/files/92844194975.pdf
    • https://cdn.shopify.com/s/files/1/0433/4046/4281/files/4079411503.pdf
    • https://cdn.shopify.com/s/files/1/0435/3631/8616/files/whirlpool_duet_washer_and_dryer_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/6338/6017/files/norton_security_and_antivirus_android_review.pdf
    • https://cdn.shopify.com/s/files/1/0433/6982/4414/files/63595909184.pdf
    • https://cdn.shopify.com/s/files/1/0431/7046/3895/files/risijugurosudituravol.pdf
    • https://65c2d4cf-cfc8-49f8-a521-0a3e827fa89b.filesusr.com/ugd/dec231_e56831a182ec4d2c8a27a9c03e4442ae.pdf?index=true
    • https://51bc2381-325d-4909-8f59-2f32030b97b7.filesusr.com/ugd/229b11_dfe12a571bc746ca948835e5741cf367.pdf?index=true
    • https://11fdc3d4-6dda-4f31-8375-e61064ab00d9.filesusr.com/ugd/dad7b5_31906da0ba254505941cc5ff58bc168d.pdf?index=true
    • https://5d42b773-d076-496e-815a-9d13fd584256.filesusr.com/ugd/82e28d_8e44132a6f464c18a57d72945603db37.pdf?index=true
    • https://dc074d60-9ee7-4bb8-a34c-d65c53e45f0b.filesusr.com/ugd/1a1092_b8e10a4334724dd1a974879b169de8ee.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000651e.bin
236efd8ced4e361dff855daed0e0767f69b40294a61baaea6b5fe5f6ba509fa9
pdf-font-stream PDF embedded font (sfnt) at offset 0x651E 4916 bytes
font_01_sfnt_off000075c7.bin
a4ec417537e2e699f5abbea803f07c68a55cb5b1d66e556e2da1068548177cfa
pdf-font-stream PDF embedded font (sfnt) at offset 0x75C7 10960 bytes