Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a5a77c7373176f2…

MALICIOUS

PDF

41.8 KB Created: 2020-08-29 21:37:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d869d1159b568abcbb3e83d76efdce9c SHA-1: f998cbe6bd39a06f1e4bffec365aecc7a040cea5 SHA-256: 7a5a77c7373176f27befa04cfddbe47f793857def9c3fb5e15b9d8385351e13e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, with one pointing to a known malicious redirector infrastructure. The document body, though heavily obfuscated, contains text suggesting a lure related to 'family tree craft template' and includes the malicious URL. The presence of numerous external PDF links further supports a link farm or redirection tactic.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=family+tree+craft+template
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/b8c837_737c091a25834ef7bf01ab27edcd084b.pdf
    • https://static.usrfiles.com/ugd/b8c837_b19415cbbbb84587b00bd428bcd33622.pdf
    • https://static.usrfiles.com/ugd/b8c837_0e24aa007528423bae5fd38d9a800efd.pdf
    • https://static.usrfiles.com/ugd/b8c837_e69b6209cd574684a9dd363513b41473.pdf
    • https://static.usrfiles.com/ugd/3b47cb_89175d37aed843edbaf6be3d35750a3c.pdf
    • https://static.usrfiles.com/ugd/b8c837_6fa6dc405ed3443ebdf37def48f500db.pdf
    • https://static.usrfiles.com/ugd/b8c837_d76afc95570843bbb83e292015836584.pdf
    • https://cdn.shopify.com/s/files/1/0438/5102/2501/files/lelujeropilagad.pdf
    • https://cdn.shopify.com/s/files/1/0431/5794/6522/files/16418016750.pdf
    • https://cdn.shopify.com/s/files/1/0429/4295/5687/files/wumibufokepibofenabej.pdf
    • https://cdn.shopify.com/s/files/1/0433/5910/9279/files/3500900798.pdf
    • https://cdn.shopify.com/s/files/1/0429/5399/8487/files/bajeluku.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/nemevisofopanufu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006662.bin
137f4af7342a40f2440ff0268842fd3c738bbe2231dedb179d979df77b499a33
pdf-font-stream PDF embedded font (sfnt) at offset 0x6662 5040 bytes
font_01_sfnt_off0000777f.bin
9de1b1b4e60d2e1481193f8a39b52f7f443f4170fe0ca2198081668dbf76f878
pdf-font-stream PDF embedded font (sfnt) at offset 0x777F 10352 bytes