Malicious PDF — malware analysis report

Static analysis result for SHA-256 a934edb1064afd3b…

MALICIOUS

PDF

42.0 KB Created: 2020-11-01 07:42:09 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7a8d21d3da9274c85ecf35139affd3e3 SHA-1: 52ecff3dbfb67e5eb70ceffd28e58f6f22ade2be SHA-256: a934edb1064afd3b2fe16ae7790f97057c9822853e8b01a9c29f36ad436b91f6
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm and a direct link to a known malicious redirector, disguised with keywords related to 'Minecraft'. The ML classifier strongly indicated maliciousness, and the presence of numerous external links suggests an attempt to drive traffic to potentially harmful sites. No scripts were extracted, but the document's structure and embedded links are indicative of a phishing or scam attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/123?keyword=minecraft+free+unblocked+at+school
    • https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/34beae5db0b367.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/satedafadusizo/arusha_declaration.pdf
    • https://uploads.strikinglycdn.com/files/b3cf3d80-ae47-4e31-900d-d98ef9447781/2019430155.pdf
    • https://s3.amazonaws.com/lopadivupudexa/pagowabi.pdf
    • https://s3.amazonaws.com/dazutun/calaveras_literarias_mexicanas.pdf
    • https://uploads.strikinglycdn.com/files/fce786e3-1096-4eac-920a-b4f4a48432ca/87859126636.pdf
    • https://uploads.strikinglycdn.com/files/91a5e8b2-4de2-4297-af34-c71370153738/funomefuboj.pdf
    • https://s3.amazonaws.com/sigobija/10566457382.pdf
    • https://s3.amazonaws.com/fekazudabo/the_complete_guide_to_aromatherapy_third_edition.pdf
    • https://uploads.strikinglycdn.com/files/a0b99f30-3d6d-40aa-b760-bbd284c8357f/13905002710.pdf
    • https://s3.amazonaws.com/dudigonifu/61706521051.pdf
    • https://s3.amazonaws.com/potevip/63922104423.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000058e6.bin
a893f0d5ed15a9318670d0f771723675eb375e1f8a328d11d712eb95132577ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x58E6 5200 bytes
font_01_sfnt_off00006a7f.bin
761397d3569cbf9ee68cb63aec949b29165005da6ee0dd14843c5e661dedff58
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A7F 10112 bytes
font_02_sfnt_off00008d10.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D10 4324 bytes