Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f614ed7b7011eaf…

MALICIOUS

PDF

29.5 KB Created: 2020-09-09 08:33:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7ada6bb42eab6e9267f40e811704d4f8 SHA-1: 7e0fc06d9cceffe62708da76466582580b2d5f5d SHA-256: 5f614ed7b7011eafd27706140d4524c6df71817dd02bdf465629dfacaf9db87b
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.001 User Execution: Malicious Link

The PDF is identified as an image-only lure, typical of phishing attacks. It contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/wix?keyword=bassinet+sheets+target'. The document also features a link farm with numerous external PDF links, suggesting an attempt to manipulate search engine results or distribute further malicious content. No scripts were extracted, but the primary malicious action is the redirection to a known malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 29 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=bassinet+sheets+target
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/b8c837_84d00b0aba554ca59aefe89adaa1aa86.pdf
    • https://static.usrfiles.com/ugd/e8506d_741943eaf02342929131156e1d036d32.pdf
    • https://static.usrfiles.com/ugd/d5cf39_b35de9497e0d4fdfb99e39ab21865755.pdf
    • https://static.usrfiles.com/ugd/610d21_b9f059edc6424aaea661e3a6a14b5efe.pdf
    • https://static.usrfiles.com/ugd/432b07_5cf333b863bb43c08be76f5fc40e3af9.pdf
    • https://cdn.shopify.com/s/files/1/0431/6332/0469/files/7957294807.pdf
    • https://cdn.shopify.com/s/files/1/0432/5313/7570/files/martin_garrix_prximos_eventos.pdf
    • https://cdn.shopify.com/s/files/1/0432/1827/2417/files/posekele.pdf
    • https://static.usrfiles.com/ugd/b8c837_a5b6b2e2ebab4cee956829f534e28626.pdf
    • https://static.usrfiles.com/ugd/694d5d_5d432bd2f00e4b419b4abf0211ebac33.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003e32.bin
7d18e5fe3a5d2c64c5a7da4d14f72b74695119f66e8888d7ddaccb510cbd9f8c
pdf-font-stream PDF embedded font (sfnt) at offset 0x3E32 4964 bytes
font_01_sfnt_off00004f0e.bin
ba1f686b610f64cd45d3d08f2fdd719d1c649fa3093f411eb840f3c2dcc0ad9e
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F0E 7908 bytes