Malicious PDF — malware analysis report

Static analysis result for SHA-256 8528cc87ae8b853a…

MALICIOUS

PDF

40.7 KB Created: 2020-08-08 03:59:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 031c38a85f02e58ab2d0f52b90a749a3 SHA-1: 27850507126e2e2f3c8c0d792d11aa97155a2a51 SHA-256: 8528cc87ae8b853a1b74365820820e316d95a81f32c2f5c76455b9c05a4fa8bf
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a significant number of embedded URLs, with one identified as a malicious redirector. The heuristic firings indicate a PDF link farm, suggesting the document's primary purpose is to distribute traffic to numerous external resources, potentially for SEO manipulation or to host malicious content. No scripts were extracted, and the document body is heavily obfuscated.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=summary+of+the+poem+the+road+not+taken+pdf
    • http://files.lifecycleaquatics.com/uploads/1/3/2/7/132740350/fiboxeposaz_mogegagas.pdf
    • http://files.envisiononeness.com/uploads/1/3/1/0/131070561/1388295.pdf
    • http://files.jwphotogallery.net/uploads/1/3/0/7/130775633/9056463.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0435/7314/9859/files/joint_munitions_effectiveness_manual.pdf
    • https://cdn.shopify.com/s/files/1/0437/1172/5723/files/wurisurefalanekapofabaga.pdf
    • https://cdn.shopify.com/s/files/1/0437/4691/8551/files/social_factors_affecting_consumer_buying_behaviour.pdf
    • https://cdn.shopify.com/s/files/1/0432/5575/9011/files/42263856378.pdf
    • https://cdn.shopify.com/s/files/1/0429/0081/6028/files/install_compass_mac.pdf
    • https://cdn.shopify.com/s/files/1/0430/7622/3129/files/fuxobujorokapefinul.pdf
    • https://cdn.shopify.com/s/files/1/0432/0791/7729/files/34945464334.pdf
    • https://cdn.shopify.com/s/files/1/0433/0035/6251/files/48496512847.pdf
    • https://cdn.shopify.com/s/files/1/0433/3119/0952/files/89014097941.pdf
    • https://cdn.shopify.com/s/files/1/0428/4396/3555/files/82959306430.pdf
    • https://cdn.shopify.com/s/files/1/0433/8316/0995/files/64843624972.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000062bc.bin
7c27c0cf6c1dc42be02acc6dcdfd5244d0c048f8b4f58664fe8f870c809385a7
pdf-font-stream PDF embedded font (sfnt) at offset 0x62BC 5340 bytes
font_01_sfnt_off000074c3.bin
d90f92771093b27087587e3086150196e3772c8f1c32882cc12e37758142a6bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x74C3 9772 bytes