Malicious PDF — malware analysis report

Static analysis result for SHA-256 5d4e1ffb20d25e1a…

MALICIOUS

PDF

41.4 KB Created: 2020-09-01 09:58:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6e7b2b120b06c2ec5766654a89b54724 SHA-1: 0225a0f61f82fc8fd557ea089db4d875b199423b SHA-256: 5d4e1ffb20d25e1a72ee9ce8b988f1f0cabf2395ae25cd3e4bd8dce4d635e563
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, one of which points to a known malicious redirector infrastructure. The document body, though heavily obfuscated, contains text that appears to be a lure for a wallpaper app, and the primary malicious URL is also present in the document body. The ML classifier strongly indicated maliciousness, and the PDF structure suggests it's designed to host numerous external links, likely for SEO manipulation or to distribute further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=best+hd+wallpaper+app+android
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0436/2944/5273/files/cricket_rules_book_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/gaxasukazojolivuf.pdf
    • https://cdn.shopify.com/s/files/1/0450/7212/2006/files/xetovigosokutibiwe.pdf
    • https://cdn.shopify.com/s/files/1/0437/6707/0877/files/28423294829.pdf
    • https://static.usrfiles.com/ugd/f84671_d44da213459c443db2c20a35034fa1c8.pdf
    • https://cdn.shopify.com/s/files/1/0437/1818/1016/files/82871392469.pdf
    • https://cdn.shopify.com/s/files/1/0431/3694/2234/files/37792215245.pdf
    • https://cdn.shopify.com/s/files/1/0436/2112/2211/files/89894821874.pdf
    • https://cdn.shopify.com/s/files/1/0437/8089/8973/files/46110656018.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006431.bin
7f8326ba8b40eb6f025745939d2bf853f69fc52c90b0d05ea840f8a252d42d03
pdf-font-stream PDF embedded font (sfnt) at offset 0x6431 5188 bytes
font_01_sfnt_off000075e3.bin
5febd43276dfb5cadaacbf2b716065cc55ea4d6136656db3c228273a46b3e7d2
pdf-font-stream PDF embedded font (sfnt) at offset 0x75E3 10292 bytes