Malicious PDF — malware analysis report

Static analysis result for SHA-256 680957e34e8f24aa…

MALICIOUS

PDF

40.4 KB Created: 2020-09-18 13:22:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8b53ea1e513865674858f5b210a16bf1 SHA-1: b40530b89c49cbecd3e67ce8c7afaaee396789d6 SHA-256: 680957e34e8f24aad3b516bfbf646886c001cdfab795bce956cadca41f5f101e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link that redirects to a malicious URL, disguised with keywords like 'unblocked games'. This URL is part of a link farm, suggesting an attempt to manipulate search engine results or lure users. The ML classifier strongly indicated maliciousness, and the PDF structure itself contains multiple embedded links, reinforcing the phishing or scam attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=unblocked+games+76+1v1+lol
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0432/2626/7806/files/58701790956.pdf
    • https://cdn.shopify.com/s/files/1/0438/1625/5645/files/adobe_photoshop_cs2_shortcut_keys_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/0574/7095/files/samsung_tv_remote_android_free.pdf
    • https://cdn.shopify.com/s/files/1/0432/5897/0280/files/48682824602.pdf
    • https://cdn.shopify.com/s/files/1/0438/6711/1584/files/11977919051.pdf
    • https://cdn.shopify.com/s/files/1/0431/7508/4193/files/brown_dust_ogdoad_guide.pdf
    • https://cdn.shopify.com/s/files/1/0438/3280/3488/files/spongebob_secret_box.pdf
    • https://cdn.shopify.com/s/files/1/0431/1931/3062/files/critical_thinking_in_education.pdf
    • https://cdn.shopify.com/s/files/1/0433/9020/6117/files/55208113323.pdf
    • https://cdn.shopify.com/s/files/1/0429/9633/4753/files/lilazud.pdf
    • https://cdn.shopify.com/s/files/1/0429/2847/2220/files/lepedutifedesonenix.pdf
    • https://cdn.shopify.com/s/files/1/0429/1087/5815/files/simon_chimbetu_lullaby.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005337.bin
6b4de89cb959dd2bc7fce729b82ec6e0c9bea7343c4b158a3d51d1e012b36716
pdf-font-stream PDF embedded font (sfnt) at offset 0x5337 5364 bytes
font_01_sfnt_off00006568.bin
cc1923bbe14a5fd9196c5bddc2ce05adea453f392cfea73d2949562fc463f32e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6568 9868 bytes
font_02_sfnt_off0000871b.bin
ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230
pdf-font-stream PDF embedded font (sfnt) at offset 0x871B 4324 bytes