Malicious PDF — malware analysis report

Static analysis result for SHA-256 729d7e82c1c92e56…

MALICIOUS

PDF

50.8 KB Created: 2020-09-17 19:16:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 28f61a4441aab35cb5710c2ce20b92ce SHA-1: 703670e2367ad46624780952b07ff0569f4b5160 SHA-256: 729d7e82c1c92e562b59649bebc2703b35b1a3dd8ce63afd13fa94e120b4afe9
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a deceptive link disguised as a search result for a local bus schedule, which redirects to a malicious URL. It also functions as a link farm, hosting numerous other PDFs on disposable domains, suggesting an attempt to manipulate search engine results or distribute further malicious content. The ML classifier strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=shafer+bus+schedule+endicott+ny
    • http://files.kalamazooneurofeedback.com/uploads/1/3/0/7/130776499/fojasawog.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://95e46872-09e0-4a7b-b427-7679ce99fbc4.filesusr.com/ugd/0d018b_cb5e60d6000b4c0e8a9c6f15a35ed3e4.pdf?index=true
    • https://cdc04b0a-e5aa-4c14-a4a1-139f82efee9f.filesusr.com/ugd/76de1a_313c3b9368a24d8fb48ed7099fd600de.pdf?index=true
    • https://c26f8a57-6ec8-4607-a79d-3642e3ed3e68.filesusr.com/ugd/b27199_02a646926379476cace9a7985ff23d4e.pdf?index=true
    • https://c30a74ec-1a4d-4a1d-99a4-672c67559dcf.filesusr.com/ugd/7e0eb0_b7435634154c4071b246ca175e59df4e.pdf?index=true
    • https://c09db502-76bc-473d-89dc-009c7a45c3a1.filesusr.com/ugd/f08e01_00502e60e78949c68f061a52a6eec4be.pdf?index=true
    • https://74e63c59-64c7-4af0-a2eb-c60c6e5d3935.filesusr.com/ugd/8db125_069d68a3108345aaa7134356b9557220.pdf?index=true
    • https://0de33dc8-1ae5-4bbf-a096-1e979bd6bd81.filesusr.com/ugd/23b571_1a5b9c5ed3834b8792f7d47850700497.pdf?index=true
    • https://4ae5a20e-6764-4ec4-8b01-9c7529a94cc3.filesusr.com/ugd/80bfa9_4245df53cec44fad86b53369f6b08c02.pdf?index=true
    • https://e833b0fd-f9e6-48b7-948a-d85a654b4a36.filesusr.com/ugd/911c12_7bbfba1556df4657b67419f2e89bb542.pdf?index=true
    • https://a5aab223-06d3-4fe6-8b73-14fe1f70821c.filesusr.com/ugd/8e7730_7930814364ec4aa5a03775ff180d4ebf.pdf?index=true
    • https://bb9dda0e-3a01-4d92-8a31-44215b518c21.filesusr.com/ugd/003b86_daf1bc7fc6a748aa9f41cfc7dda0278f.pdf?index=true
    • https://4083bad9-e2cd-40d9-9a9f-8a3e78bb40a0.filesusr.com/ugd/d1c05f_3f5e4bbe917d47cdb18583fd87395676.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ec9.bin
8645305ac073052b5cecf98092af570dd93513937f51a748d44f048d3ec812db
pdf-font-stream PDF embedded font (sfnt) at offset 0x6EC9 5336 bytes
font_01_sfnt_off000080de.bin
0ceea40b73ec8283f4d496190630856e1c9aebf5de7c7a6b693f32445f67447d
pdf-font-stream PDF embedded font (sfnt) at offset 0x80DE 15328 bytes
font_02_sfnt_off0000b004.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0xB004 4324 bytes