Malicious PDF — malware analysis report

Static analysis result for SHA-256 c530f1ddbd1fa102…

MALICIOUS

PDF

48.1 KB Created: 2020-08-31 09:39:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 33f68d2bfe1e2590630baf4491ec5c92 SHA-1: 33f228a748902a97a33c54da0bc6edb47bea9218 SHA-256: c530f1ddbd1fa102fde853af675869726594cb0aa3a24ed92e4bb233250d8cb5
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged as malicious by a machine learning classifier and contains a critical heuristic indicating a link to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains the same URL found in the heuristic. The presence of numerous other links to Shopify PDFs suggests an attempt to disguise the malicious link within a larger link farm, likely for SEO poisoning or to appear more legitimate.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=singer+66+red+eye+treadle+sewing+machine
    • https://cdn.shopify.com/s/files/1/0429/8070/4405/files/xojupisesegototaso.pdf
    • https://cdn.shopify.com/s/files/1/0432/2505/5389/files/24710771111.pdf
    • https://cdn.shopify.com/s/files/1/0432/9635/8565/files/nupafaluxu.pdf
    • https://cdn.shopify.com/s/files/1/0434/1058/7800/files/6778068764.pdf
    • https://cdn.shopify.com/s/files/1/0432/6886/6212/files/application_form_passport_post_office.pdf
    • https://cdn.shopify.com/s/files/1/0433/7152/8344/files/85106486459.pdf
    • https://cdn.shopify.com/s/files/1/0429/6943/2230/files/capacity_building_meaning.pdf
    • https://cdn.shopify.com/s/files/1/0467/8090/7673/files/725263268.pdf
    • https://cdn.shopify.com/s/files/1/0440/6280/2085/files/chemische_formeln_erstellen_word.pdf
    • https://static.usrfiles.com/ugd/d9d1f5_2c12e07eeadc4be597e0ca0334cdccfa.pdf
    • https://static.usrfiles.com/ugd/91e123_f35b0362464c4db3bc41ef6b23cfc4df.pdf
    • https://static.usrfiles.com/ugd/b8c837_a7e816df90f84078a149fb3bc402d79b.pdf
    • https://static.usrfiles.com/ugd/0779a3_efabeeadc42b4274a6b9ae753c9b12c8.pdf
    • https://static.usrfiles.com/ugd/930050_28792eab831c4b8b9da939da3b37011a.pdf
    • https://cdn.shopify.com/s/files/1/0433/3702/3641/files/bypass_google_account_apk_android_7.pdf
    • https://cdn.shopify.com/s/files/1/0433/3866/2053/files/62085481287.pdf
    • https://cdn.shopify.com/s/files/1/0438/5298/8566/files/autocad_architecture_2016_trial.pdf
    • https://cdn.shopify.com/s/files/1/0430/1747/0101/files/tikib.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007ad4.bin
31a3501818e907547404be05ab23ca5f42da71b43b2c79e15ea1941c3d282cb6
pdf-font-stream PDF embedded font (sfnt) at offset 0x7AD4 5804 bytes
font_01_sfnt_off00008e74.bin
92f811efe266f2fe633b6ef44cb234cc5534b7346234782f13dd47d490ccfc80
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E74 11136 bytes