Malicious PDF — malware analysis report

Static analysis result for SHA-256 2772dabc399db81e…

MALICIOUS

PDF

41.2 KB Created: 2020-08-30 22:11:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fab1019ccf9b036d65c860f563b2ab03 SHA-1: 72712b2470c9ab9ffd0f848759e716a95c826f93 SHA-256: 2772dabc399db81e6f0693f3fb8660c72974e195b5dd37a95c41e38233a52082
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1200 Hardware Add-in T1059.001 PowerShell

The PDF file contains a critical heuristic firing indicating a link to known malicious redirector infrastructure. Additionally, it features a PDF link farm, with the primary link pointing to a suspicious URL. The ML classifier also strongly flagged this PDF as malicious. While no scripts were extracted, the presence of these malicious links suggests the document is designed to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=tri-point+double-edged+sword
    • https://cdn.shopify.com/s/files/1/0435/0076/5336/files/dusesozasisinokibofomev.pdf
    • https://cdn.shopify.com/s/files/1/0450/3106/3716/files/canada_child_passport_application.pdf
    • https://cdn.shopify.com/s/files/1/0432/3190/3902/files/acta_constitutiva_formato.pdf
    • https://static.usrfiles.com/ugd/b8c837_7ba1d084c5234a77990e9413f8821f85.pdf
    • https://static.usrfiles.com/ugd/3b7182_58c73f4b482640669ff0a69595e4788e.pdf
    • https://static.usrfiles.com/ugd/b8c837_88218eff24bf439d88857ad7bd5bbd51.pdf
    • https://static.usrfiles.com/ugd/b8c837_1008a45593a0482ba727a4884fcec52b.pdf
    • https://static.usrfiles.com/ugd/b8c837_60fce5d3d096494685c0eb07b89e421d.pdf
    • https://static.usrfiles.com/ugd/6cf0f5_e4913e9d06d5421687c7de39c9232ad1.pdf
    • https://static.usrfiles.com/ugd/74e905_46913775540648d08f500fb4b1bc9f1c.pdf
    • https://static.usrfiles.com/ugd/07625c_e9cb1a2978cc42c0b0f988cc401558c7.pdf
    • https://static.usrfiles.com/ugd/b8c837_951e570927e8432a904e5e6ccbc294f8.pdf
    • https://cdn.shopify.com/s/files/1/0427/4877/2508/files/banff_national_park_hiking_map.pdf
    • https://cdn.shopify.com/s/files/1/0433/9331/9079/files/dodujixeb.pdf
    • https://cdn.shopify.com/s/files/1/0437/3826/7809/files/android_studio_setup_jdk_path.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005791.bin
3d40fd28dd91e68e4a1602ff33ea90089432a279bf2090babe0d6455bbe1e52c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5791 3024 bytes
font_01_sfnt_off00006260.bin
579a94b68176ad87b3d5e4ba5671d0eefb667c465b66a18ebe3d68a987f489f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x6260 5128 bytes
font_02_sfnt_off000073f0.bin
05a5bc31ea39c1467101c67cb11f53039951d1c9b27a80f3b1c7435f5106919b
pdf-font-stream PDF embedded font (sfnt) at offset 0x73F0 10504 bytes