Malicious PDF — malware analysis report

Static analysis result for SHA-256 80650b8294ff7c36…

MALICIOUS

PDF

56.0 KB Created: 2020-08-30 21:43:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a383360bce769b0abd778d7a2a590fb3 SHA-1: a1c28481c7e1fa5c61c84130ccb3a0792725840e SHA-256: 80650b8294ff7c369b82297132940b68c428e3ec785967680d12980e84a0f821
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, one of which points to a known malicious redirector. The document body, though heavily obfuscated, contains text suggesting it's an 'acknowledgement letter' and includes the malicious URL. The presence of numerous external PDF links, many benign but some potentially malicious, indicates a link farm strategy. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=acknowledgement+letter+after+receiving+documents
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/b8c837_db0f21ed758f4bd0b9a393ee819e4285.pdf
    • https://static.usrfiles.com/ugd/b8c837_7774b715a74c49508704fffbc00571e5.pdf
    • https://static.usrfiles.com/ugd/067ecb_085a4144046346f7b927f719077cb740.pdf
    • https://cdn.shopify.com/s/files/1/0429/0645/2131/files/23620138032.pdf
    • https://cdn.shopify.com/s/files/1/0429/3004/5091/files/86892481479.pdf
    • https://cdn.shopify.com/s/files/1/0430/7235/6514/files/91087920306.pdf
    • https://cdn.shopify.com/s/files/1/0433/5419/4070/files/pojuwerepiwodo.pdf
    • https://cdn.shopify.com/s/files/1/0434/4971/2807/files/lusavemuzuz.pdf
    • https://cdn.shopify.com/s/files/1/0430/8815/0690/files/jibenazebikibaneninunije.pdf
    • https://cdn.shopify.com/s/files/1/0432/1751/8751/files/how_to_update_netgear_router.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009343.bin
a17885b4fd577e0298a64705d5055d2ac7c2363fd7008e9cf236b3df412a17d8
pdf-font-stream PDF embedded font (sfnt) at offset 0x9343 2828 bytes
font_01_sfnt_off00009d3d.bin
e44c2649458d40fff6e0e5025d512f0d1f32a4c0173be43e59c5449bb51f19ec
pdf-font-stream PDF embedded font (sfnt) at offset 0x9D3D 5548 bytes
font_02_sfnt_off0000b016.bin
2a3e9d6cabb8b928d5937842f3b8c875955f130589e49d1dabd1072e33930a33
pdf-font-stream PDF embedded font (sfnt) at offset 0xB016 10024 bytes