Malicious PDF — malware analysis report

Static analysis result for SHA-256 6051cdfa07167d9b…

MALICIOUS

PDF

43.5 KB Created: 2020-09-07 00:25:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 64edea8809bf2e749f69a1196a89d823 SHA-1: 1d4bc322c9c041b68a50ebbae480b9128484cb52 SHA-256: 6051cdfa07167d9b3cafa185cbece3be186c7684d06e5ea6bad79444ac0a8c12
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains embedded URLs, including one pointing to a known malicious redirector. The document body, though heavily obfuscated, contains text suggesting a lure related to a sports match report. The presence of a link farm heuristic further indicates malicious intent to redirect users to potentially harmful content. No scripts were extracted, but the overall structure and embedded links suggest a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=manchester+united+vs+rochdale+match+report
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0433/9823/4270/files/60455329744.pdf
    • https://cdn.shopify.com/s/files/1/0432/1892/7775/files/vosonanaz.pdf
    • https://cdn.shopify.com/s/files/1/0433/0346/9221/files/50606669340.pdf
    • https://cdn.shopify.com/s/files/1/0430/4293/0842/files/1639635226.pdf
    • https://cdn.shopify.com/s/files/1/0437/6880/7586/files/how_to_apply_for_a_job_via_email.pdf
    • https://cdn.shopify.com/s/files/1/0435/8704/3496/files/kirofewaka.pdf
    • https://cdn.shopify.com/s/files/1/0463/9073/9099/files/mixed_grammar_exercises_with_answers.pdf
    • https://cdn.shopify.com/s/files/1/0436/0319/8114/files/japanese_skincare_revolution_tips.pdf
    • https://cdn.shopify.com/s/files/1/0437/5193/2056/files/algebraic_expressions_worksheet_7th_grade.pdf
    • https://static.usrfiles.com/ugd/32acb1_c7fef8fdc7454e0e887ce71d12bc4e35.pdf
    • https://static.usrfiles.com/ugd/dcfb95_ca674204ac514f769852aba27f609162.pdf
    • https://static.usrfiles.com/ugd/abd6ea_6a921cb214de47928078ba98754b3e4b.pdf
    • https://static.usrfiles.com/ugd/948cea_2e15f61e149948588ac3c183caf7c3d1.pdf
    • https://cdn.shopify.com/s/files/1/0437/3803/8423/files/73457837348.pdf
    • https://cdn.shopify.com/s/files/1/0429/1097/4111/files/13367911591.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ad9.bin
64a56cf48ebc68b9585466ce3e56d988d722e4abcc30cbed8569760048def0df
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AD9 5380 bytes
font_01_sfnt_off00007d09.bin
5a6ed1b748b0c464581adb4ba6d8c7f3cd2466e7d026485ff7d520176a5f410a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D09 10452 bytes