Malicious PDF — malware analysis report

Static analysis result for SHA-256 786d719847abbb01…

MALICIOUS

PDF

64.0 KB Created: 2020-08-30 11:50:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8994681690c42890b5ca2cec544763df SHA-1: 831636a2fa8c2c1c4af62c8548854ae134d2fb00 SHA-256: 786d719847abbb01d91fa83154fc53937e969f4017aaf462d68496605b2b1c64
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded links, with one pointing to a known malicious redirector. The heuristic PDF_SEO_LINK_FARM indicates a large number of external links, suggesting an attempt to manipulate search engine results or distribute malicious content. The ML classifier also strongly flagged this PDF as malicious. The primary malicious IOC is the redirector URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=shantung+compound+chapter+summaries
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0435/1298/7802/files/adaptor_for_android_phone_to_tv.pdf
    • https://cdn.shopify.com/s/files/1/0440/5959/0806/files/evil_dead_tamil_movie_hd_print.pdf
    • https://cdn.shopify.com/s/files/1/0431/1361/1421/files/rokewuduganewurabegozix.pdf
    • https://cdn.shopify.com/s/files/1/0438/2598/7741/files/acrobat_reader_files_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0443/6351/4012/files/bazowiwekanalavefevulev.pdf
    • https://cdn.shopify.com/s/files/1/0436/9245/8152/files/sonda_vesical_procedimento.pdf
    • https://cdn.shopify.com/s/files/1/0435/5814/2120/files/66301246129.pdf
    • https://cdn.shopify.com/s/files/1/0430/7881/1810/files/sagixojorezumadutuxi.pdf
    • https://cdn.shopify.com/s/files/1/0434/2880/6806/files/age_of_empires_validating_subscriptions.pdf
    • https://static.usrfiles.com/ugd/544c7e_e27b864f3b184fc09c0c7f7983a60633.pdf
    • https://static.usrfiles.com/ugd/b8c837_ccf468dcf2bc49ac84922b3fc48405da.pdf
    • https://static.usrfiles.com/ugd/bf0735_8113947c37164cbaba12369491ceeab1.pdf
    • https://static.usrfiles.com/ugd/a382ee_9fb3c23e664045338c88936448dfc380.pdf
    • https://static.usrfiles.com/ugd/19ce5d_d92e07412d2c4d4f851570293b9571d2.pdf
    • https://static.usrfiles.com/ugd/b8c837_89c8ccee109b40e9ad89d3b19b6d3d23.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bc61.bin
65ba47ee7268c54cfb1ee6e137bab7d81366ad18f494acdc9ea5165b44569a28
pdf-font-stream PDF embedded font (sfnt) at offset 0xBC61 5556 bytes
font_01_sfnt_off0000cf0e.bin
f151cc5fb536ee4313d9641c271da32ca9a9026964cd6a97a331a278938083c8
pdf-font-stream PDF embedded font (sfnt) at offset 0xCF0E 10444 bytes