Malicious PDF — malware analysis report

Static analysis result for SHA-256 a082e721887ffda1…

MALICIOUS

PDF

34.1 KB Created: 2020-08-17 03:08:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0b77a7a3cb992b263307fc32eef6b0d9 SHA-1: 6be34001291c964a7e7fc2c1c0f2417b5c266b62 SHA-256: a082e721887ffda12a505cc3fd1370e27652da465e624ba72eb2df3c8e41b41b
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of embedded links, with a heuristic identifying it as a PDF link farm. One of the primary links directs to a known malicious redirector. The ML classifier also strongly flagged this PDF as malicious. The document body contains obfuscated text and URLs, including the malicious redirector and numerous links hosted on Shopify, suggesting a campaign focused on link manipulation and redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=sheetz+elysburg+contact
    • http://files.olgaolgaolga.co.nz/uploads/1/3/2/3/132303010/voxemofiromitovudute.pdf
    • http://files.capecurbappeal.com/uploads/1/3/2/7/132741144/d0cd9acb7.pdf
    • http://files.bellereidfarm.com/uploads/1/3/0/7/130775876/wopixapinikex-giduvilutox-bokevifebe.pdf
    • https://cdn.shopify.com/s/files/1/0437/4901/5713/files/mibomamanevuto.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/gekisemegudifusoledo.pdf
    • https://cdn.shopify.com/s/files/1/0431/9212/3554/files/1752376739.pdf
    • https://cdn.shopify.com/s/files/1/0435/3641/6936/files/12th_maths_formulas_list_hsc.pdf
    • https://cdn.shopify.com/s/files/1/0429/5625/9491/files/94728470758.pdf
    • https://cdn.shopify.com/s/files/1/0429/9961/1553/files/asimov_s_guide_to_the_bible.pdf
    • https://cdn.shopify.com/s/files/1/0430/0151/2095/files/mirebelamefosopukiraluj.pdf
    • https://cdn.shopify.com/s/files/1/0432/8367/7339/files/rixexurije.pdf
    • https://cdn.shopify.com/s/files/1/0434/2117/1879/files/9266756856.pdf
    • https://cdn.shopify.com/s/files/1/0434/6881/6544/files/vukojokekinumiwitutagu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000464a.bin
d9ca8363d254cf0dd6e77010ca1dd46a4d4f19d00ea58ab1436a6437edf10b0d
pdf-font-stream PDF embedded font (sfnt) at offset 0x464A 5456 bytes
font_01_sfnt_off000058df.bin
d694190e5f09a2687d284c2765977398efb0982fd312b4f74322f83abc35819d
pdf-font-stream PDF embedded font (sfnt) at offset 0x58DF 10244 bytes