Malicious PDF — malware analysis report

Static analysis result for SHA-256 1344059415d7417f…

MALICIOUS

PDF

38.5 KB Created: 2020-09-17 18:25:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fc1eb771f1ef2d23c25a4e7386fff5b0 SHA-1: 4d5b190e205d0389a80b48a699842a6a1247e3e7 SHA-256: 1344059415d7417f6cdbb5aaf74a0590ff5c88798235b6711b70eb834c04f9b9
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, with one identified as a malicious redirector. The document body, though heavily obfuscated, contains text suggesting it is a 'worksheet answers' lure, which is consistent with the malicious redirector URL. The presence of many external PDF links suggests a link farm, likely for SEO poisoning or to distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=colliding+continents+worksheet+answers
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://9164c612-288a-4f7e-807e-2d1ba8e6f40e.filesusr.com/ugd/a64c8c_7a236f1c5bd1412390df91bd401f388f.pdf?index=true
    • https://367cf621-9f51-451b-9675-4605f4022430.filesusr.com/ugd/3f0e57_96a27e1ffa7b4716963bf670fd82dd5a.pdf?index=true
    • https://15e484d6-da60-4287-9ecf-fd44edacc4af.filesusr.com/ugd/941881_9a50ba853bde49338822d7d1f7e921e1.pdf?index=true
    • https://c7d1719b-00c5-440f-9eca-e413dc13effb.filesusr.com/ugd/01e791_0f324d8aaa2044a5bf17c5433799a60c.pdf?index=true
    • https://9d11f40b-7dd6-4b2d-90a3-8d2956f2e966.filesusr.com/ugd/a42eed_3b2a384883054b819c2f285999ef8b80.pdf?index=true
    • https://4ec6b28b-d270-4e29-b42f-69f0e0ff1170.filesusr.com/ugd/9117e0_e24bbc98af414d119945f85e5fc94071.pdf?index=true
    • https://58c5327c-77e8-4095-94aa-56d6b21eb28b.filesusr.com/ugd/d51d36_bc9a8d92cb034bd9be46614636784440.pdf?index=true
    • https://ed99fcc2-34e9-4685-9501-59f88385aa84.filesusr.com/ugd/4fea5c_a9feaec8cb5041d6b2e1aac1adbcf0cb.pdf?index=true
    • https://9ce31883-9ae7-4e7e-ac55-aec38d010003.filesusr.com/ugd/eb6612_ca06fadb2ea1462d9cf578f97ecbbc54.pdf?index=true
    • https://170dc11e-794c-4245-9b7d-eeb86e4783cb.filesusr.com/ugd/fe83c3_692c88cc286344aa995265e87194f4a8.pdf?index=true
    • https://b0a8d407-9aac-4f23-8dfc-8bc191e72acc.filesusr.com/ugd/c638b7_92d3bc61e37d4945bfc746a6ed0b0997.pdf?index=true
    • https://94d1e7dc-429b-4480-99de-4e9014711929.filesusr.com/ugd/ac8c68_2fa93b2dceba441e85fe891cac7370cd.pdf?index=true
    • https://6efeb952-2415-4264-a668-9a0ace2bb1b0.filesusr.com/ugd/d7d6cd_8577ea3e5b4d4f7bb85d51d13e1a78e8.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005941.bin
98215053b4ef7fd0eaa503fcac3a51cd3a8c22395e1cc0a569e271a5a64b6e62
pdf-font-stream PDF embedded font (sfnt) at offset 0x5941 5260 bytes
font_01_sfnt_off00006b30.bin
1ee83822ed573e024adfddda899cf462a9eb9b80c4ed00d6618bb9a53e3296c1
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B30 9932 bytes