Malicious PDF — malware analysis report

Static analysis result for SHA-256 69ddb8e0729bb3ba…

MALICIOUS

PDF

49.5 KB Created: 2020-09-05 18:15:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ca2fa78d92416267756aaf0a15446172 SHA-1: ddf42ed09f83bc998dc868d7a710c4952b05f007 SHA-256: 69ddb8e0729bb3ba86dfc3741e7a4ee7780004e4d78480373f4667b008b6dd28
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a link farm and a specific malicious redirector URL, disguised as a search result for 'avira antivirus for android mobile'. This suggests a phishing or malware distribution attempt. The ML classifier strongly flagged this PDF as malicious, and the presence of embedded URLs further supports this assessment. No scripts were extracted, but the overall structure points to a lure to click on the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=avira+antivirus+for+android+mobile
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://static.usrfiles.com/ugd/7836c9_e38a4953f7b54be5a6941ec5b1d5069e.pdf
    • https://static.usrfiles.com/ugd/ef7b09_e199b3fdd5d545d7b2d1d5de825ffc52.pdf
    • https://static.usrfiles.com/ugd/6f58fb_ecc1d1c84d3845b28565e8c07924281f.pdf
    • https://static.usrfiles.com/ugd/76156b_e75fca1b04d9449fbefd7bc757aee20e.pdf
    • https://static.usrfiles.com/ugd/1df9ea_fcb823307a50418ea63c2019d6e103bd.pdf
    • https://static.usrfiles.com/ugd/599026_9d7440906233495c820cc6df752ac962.pdf
    • https://static.usrfiles.com/ugd/0779a3_6be0c1faf3034de6b02b7a27b1aca1bd.pdf
    • https://static.usrfiles.com/ugd/3ce946_169c39023c174373bccdc13c085ef9dc.pdf
    • https://static.usrfiles.com/ugd/b8c837_fcd7010f44864e0495c381b9c7c8127f.pdf
    • https://static.usrfiles.com/ugd/e02969_2206af78484b48e1bbb8d56de8142b4b.pdf
    • https://static.usrfiles.com/ugd/0a593f_430cb300560c450bb4d4691e333746ed.pdf
    • https://static.usrfiles.com/ugd/9ec29b_7a392733f964481e9369ea80071357aa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007560.bin
0dc8b0ec6eae69e21a23f155e05265a4aaaa9415b0388e27514da19ebd4590bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x7560 5124 bytes
font_01_sfnt_off000086af.bin
d1987951c95249b95fa8447d0a8535d38b5a887a894eb352a2eb2e4016c95e7a
pdf-font-stream PDF embedded font (sfnt) at offset 0x86AF 10652 bytes
font_02_sfnt_off0000ab16.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0xAB16 4324 bytes