Malicious PDF — malware analysis report

Static analysis result for SHA-256 6cf5f89db73f0f1d…

MALICIOUS

PDF

162.9 KB Created: 2020-08-31 11:41:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6ba336a9dc821fd29ea1d954f52ad705 SHA-1: 80edf73f072d812a4340ae382f1e7378db9cb04f SHA-256: 6cf5f89db73f0f1d348d0b80cc214964c8b546394b3a401406bbd486ee80d36e
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that points to known malicious redirector infrastructure. The ML classifier also flagged this PDF with high confidence. While no scripts were extracted, the presence of a malicious URL and the document's likely deceptive content indicate an attempt to redirect the user to a harmful site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=the+guild+3+mods
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://static.usrfiles.com/ugd/b8c837_665cf2c14ae843bfb5d9ccd3087f63af.pdf
    • https://static.usrfiles.com/ugd/a298ce_a247c8e7b5d8407782dcc51f324007e9.pdf
    • https://static.usrfiles.com/ugd/b8c837_2f89acf1dc964d64bbb991bcf2a82451.pdf
    • https://static.usrfiles.com/ugd/b8c837_ea71c40b953e43ccac0318b398318834.pdf
    • https://static.usrfiles.com/ugd/3b47cb_ee871598bb3d49a1aca9b2466ba65bbb.pdf
    • https://static.usrfiles.com/ugd/b8c837_23de9b25a7244af8b20cabae8e05d6d0.pdf
    • https://static.usrfiles.com/ugd/b8c837_8074e4e6fb15479d8a3e200b9c09d4bb.pdf
    • https://static.usrfiles.com/ugd/f1d680_185b08b5a51246e9959a36bf20be1fa4.pdf
    • https://cdn.shopify.com/s/files/1/0432/4897/6032/files/23671393390.pdf
    • https://cdn.shopify.com/s/files/1/0428/3603/3695/files/31653075628.pdf
    • https://cdn.shopify.com/s/files/1/0434/5459/5224/files/texas_boater_education_exam_answers.pdf
    • https://cdn.shopify.com/s/files/1/0431/1754/3588/files/pasezanafijipila.pdf
    • https://cdn.shopify.com/s/files/1/0431/3799/0813/files/bldc_motor_driver.pdf
    • https://static.usrfiles.com/ugd/3e5d97_b76cc60a521644e1a257205260b09676.pdf
    • https://static.usrfiles.com/ugd/90423f_9638ab09159b4472b9972db00b2431f0.pdf
    • https://static.usrfiles.com/ugd/b8c837_24a2109d6d6a4ef2a82f3fb2642d547c.pdf
    • https://static.usrfiles.com/ugd/b8c837_4894bbb1a51b432d995f3a6f5d64b0ce.pdf
    • https://static.usrfiles.com/ugd/b8c837_6c56ff02bb8747a39c6d409075c3bdb5.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00023151.bin
fd719362fb4b9153ff03ea5bf7fc23c7986a71d7a5deb3aaecd25d560a149ada
pdf-font-stream PDF embedded font (sfnt) at offset 0x23151 4744 bytes
font_01_sfnt_off0002416a.bin
94d5ffa276e02b4615c82d274d36ef3d8f3f1db196a9994ca91afba3d3ee7516
pdf-font-stream PDF embedded font (sfnt) at offset 0x2416A 14820 bytes
font_02_sfnt_off00026f8f.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x26F8F 4324 bytes