Malicious PDF — malware analysis report

Static analysis result for SHA-256 71245b6d90269660…

MALICIOUS

PDF

42.3 KB Created: 2020-09-17 16:59:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a14c2feda201dfd6dfb1baefb003fe42 SHA-1: b16171d8ed39692ae9c5a9f2b1de522d612c44d8 SHA-256: 71245b6d90269660e42df006f21fbd2ad6bc78cd59e24b452a7e7726af9ba449
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document contains a large number of embedded links, many of which point to a redirector infrastructure. The document body, though partially corrupted, contains text suggesting it is a generator manual, likely a lure to encourage clicking the malicious link. The ML classifier strongly indicates maliciousness, and the presence of a redirector URL confirms the intent to lead users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=husky+5000+watt+generator+manual
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://67febd19-3f36-4f15-a1c6-711911e354f7.filesusr.com/ugd/5a4aad_3652ece3d0be4b5ba62e8cb14a6d0492.pdf?index=true
    • https://d98eb94b-768e-435b-b4dc-31d5b70787be.filesusr.com/ugd/02beb7_1286a89cfdaa4d9e8c95bcbd08671eb4.pdf?index=true
    • https://064c4c64-352d-4f3f-9a02-ee782fec9b4e.filesusr.com/ugd/405339_15d91cc5026848faafe613ef7997309b.pdf?index=true
    • https://3a2ceb26-497b-4317-ac9b-bbdba20ff069.filesusr.com/ugd/2c7c49_014273d3289349e495a4eb9d2f282162.pdf?index=true
    • https://745a066a-4efc-49d7-8a93-48fc7d88b5e4.filesusr.com/ugd/33a16d_869ce7cd36c54c5fb50dfc966de24248.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0431/8547/1656/files/wezezinajotojivuf.pdf
    • https://cdn.shopify.com/s/files/1/0431/8347/2791/files/hollander_wolfe_nonparametric_statistical_methods.pdf
    • https://cdn.shopify.com/s/files/1/0432/2630/0575/files/93602138796.pdf
    • https://cdn.shopify.com/s/files/1/0429/8961/7311/files/kopupolegixeligibasederer.pdf
    • https://cdn.shopify.com/s/files/1/0428/7424/1183/files/gudizajufasosezanuzafuge.pdf
    • https://cdn.shopify.com/s/files/1/0438/6455/5675/files/molij.pdf
    • https://cdn.shopify.com/s/files/1/0432/1456/9631/files/albania_tourist_guide.pdf
    • https://cdn.shopify.com/s/files/1/0431/6109/2250/files/best_android_phone_under_15000_march_2019.pdf
    • https://cdn.shopify.com/s/files/1/0427/5847/1846/files/clip._dj_free_download_mp3_songs.pdf
    • https://cdn.shopify.com/s/files/1/0431/2956/9434/files/directed_numbers_worksheet_igcse.pdf
    • https://820a9583-fc53-45fc-8e64-11d4b3261770.filesusr.com/ugd/48bf55_93370d1c997e44c8a082e456eac2f65e.pdf?index=true
    • https://8bc435db-466c-4d73-ab37-488bf8002e25.filesusr.com/ugd/9cfd0a_9851e8eadf2c4d2aab22efac4df8c2c0.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000065ec.bin
ee139f6ac9bc7230b00424192e4bafc3acbb9a4d923b4d3b9533bec5955ef1e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x65EC 5488 bytes
font_01_sfnt_off000078a3.bin
a2c1a9030e4f448bb7c3bca531ac0f10f2fb5a54a2e22ac7c799dbdc45d3dcad
pdf-font-stream PDF embedded font (sfnt) at offset 0x78A3 10360 bytes