Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c21e8f7f3598074…

MALICIOUS

PDF

41.9 KB Created: 2020-09-05 04:30:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 44f12a89671704c76e5ad8df00438924 SHA-1: 16d9569cb21866c9a4a6234a97e176a26f288c62 SHA-256: 7c21e8f7f3598074d865284996b62d328c1b249deed1706bd58effecb1e82b9c
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm and a direct link to a known malicious redirector, suggesting an attempt to drive traffic to malicious infrastructure. The document body, though heavily obfuscated, contains URLs that appear to be part of a SEO link farm strategy, likely to disguise the malicious redirector. The ML classifier strongly indicates maliciousness, and the presence of embedded URLs points towards a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=multiplying+decimals+worksheets+fifth+grade
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0430/9689/9745/files/lopejekewiwureponin.pdf
    • https://cdn.shopify.com/s/files/1/0431/6105/9482/files/wetevasubojozij.pdf
    • https://cdn.shopify.com/s/files/1/0431/6125/6096/files/wivarofawixirikijukatavot.pdf
    • https://cdn.shopify.com/s/files/1/0431/4143/1464/files/barcode_software_full_version_free.pdf
    • https://cdn.shopify.com/s/files/1/0435/4146/3204/files/303741812.pdf
    • https://static.usrfiles.com/ugd/87ad98_c07f795dff6e4103a65bd01479c25e9b.pdf
    • https://static.usrfiles.com/ugd/d31907_6cc067f54ed24f4e9c046f3450c05a55.pdf
    • https://static.usrfiles.com/ugd/1b8612_7db4c6134c1b4abdb4066a28a71afaa4.pdf
    • https://static.usrfiles.com/ugd/90661f_e02402c6f72b4bd4aebe40859db35790.pdf
    • https://static.usrfiles.com/ugd/ba3095_c156ccdf69bd48f9b0797cf1b09680e5.pdf
    • https://static.usrfiles.com/ugd/9edd50_12094320baca4d75989168a75e20c555.pdf
    • https://static.usrfiles.com/ugd/1fa6dd_8ca25d0756694850930c6a8da91a3a79.pdf
    • https://static.usrfiles.com/ugd/724fb5_0f0fb85504314c0292866b8fd45a24c1.pdf
    • https://cdn.shopify.com/s/files/1/0429/8702/8641/files/30104708127.pdf
    • https://cdn.shopify.com/s/files/1/0431/7777/1164/files/discord_animated_emoji.pdf
    • https://cdn.shopify.com/s/files/1/0431/2681/6932/files/33907742294.pdf
    • https://cdn.shopify.com/s/files/1/0439/2953/4632/files/barbie_costumes_ideas.pdf
    • https://cdn.shopify.com/s/files/1/0431/3038/8642/files/42749752154.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000062f5.bin
46fe530def916774ad14df0040d31e07db29595eed74ed7627a0343bd181b3ac
pdf-font-stream PDF embedded font (sfnt) at offset 0x62F5 5832 bytes
font_01_sfnt_off000076ca.bin
109d230d2e3156b298ec7d334a4c18e0f30e509c72a869a28ee92fee294c3ca9
pdf-font-stream PDF embedded font (sfnt) at offset 0x76CA 10444 bytes