Malicious PDF — malware analysis report

Static analysis result for SHA-256 67e9f45ed653eecd…

MALICIOUS

PDF

223.9 KB Created: 2020-08-31 18:03:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 804bf065538dbc8a738616f871d35767 SHA-1: 3d1b2eb657d4e5d8770405f821106e265a067b45 SHA-256: 67e9f45ed653eecd55144c973dbbc623bff0e842b374efc79bebac4d2501ee73
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that points to a known malicious redirector. The document body, though heavily obfuscated, contains text that suggests an urgency lure, such as 'action required within 24 hours'. The ML classifier also strongly flagged this PDF as malicious. The primary attack vector appears to be directing the user to a malicious site via the embedded link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=platelet+transfusion+guidelines+2019
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/b8c837_bcf8ae4208574a229b816d0d778b054c.pdf
    • https://static.usrfiles.com/ugd/b8c837_514fcb85c753499db8ea586f9985d5a2.pdf
    • https://static.usrfiles.com/ugd/930050_260e6b82197a4ea68059d18e10eed50e.pdf
    • https://static.usrfiles.com/ugd/db1da1_b61d2fb7ea844196b3d53103e227239d.pdf
    • https://static.usrfiles.com/ugd/b8c837_682d915c828e49ccae42f5eabca10abc.pdf
    • https://static.usrfiles.com/ugd/b8c837_6e04b37cf8234c69b4a55d7882f1f717.pdf
    • https://static.usrfiles.com/ugd/0047a4_9df146635ad046a09aa3d039af7115bf.pdf
    • https://static.usrfiles.com/ugd/23b571_3cd6ffcb71d4477489db4998f7e3086d.pdf
    • https://static.usrfiles.com/ugd/5b9a87_61d5a3a2bc8644a2b452390645b36329.pdf
    • https://static.usrfiles.com/ugd/0fdb6d_12b31134e6e04d6c86d27245df5eaab2.pdf
    • https://static.usrfiles.com/ugd/ce5d00_b91a2603c9a145f6b4c8bc376515c064.pdf
    • https://static.usrfiles.com/ugd/0df15e_4ccfdafdd30146baba25c9b791b2046e.pdf
    • https://static.usrfiles.com/ugd/9ea91e_022d89a025a44663b5299d2c30d2081e.pdf
    • https://static.usrfiles.com/ugd/599026_1fa6f581563340f3ab33fcc0ccd4e0b7.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000313cd.bin
9094d8844736921ec8bb4fe746b70b2b4e4aa81676055242601afdcc1a6f3f61
pdf-font-stream PDF embedded font (sfnt) at offset 0x313CD 5556 bytes
font_01_sfnt_off000326c0.bin
1183db601654a83dad1fc48d0af17550619c1482863c4a6900e5a586502fb66d
pdf-font-stream PDF embedded font (sfnt) at offset 0x326C0 17164 bytes
font_02_sfnt_off00035bd4.bin
c988415812f594187b0a0ed75dc52802e798e1695b49bd300f8412a65040a449
pdf-font-stream PDF embedded font (sfnt) at offset 0x35BD4 16204 bytes