Malicious PDF — malware analysis report

Static analysis result for SHA-256 d007a3021c998cac…

MALICIOUS

PDF

48.6 KB Created: 2020-08-19 12:25:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 18be047616fded380c131527d9905a4a SHA-1: fc592ae499a6081ed0e8f22c8f803ec0d8180024 SHA-256: d007a3021c998cac1091288dc21dd2343d9bf3f9ac8a7ffebf34f84942f873b4
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass of external links, many pointing to a redirector service, indicating a link farm or phishing attempt. The ML classifier strongly flagged this PDF as malicious. The document body, though partially corrupted, contains text related to 'water filter pitcher reviews consumer reports' and the malicious URL, suggesting a lure to a scam or phishing site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=water+filter+pitcher+reviews+consumer+reports
    • http://files.tzniusprincess.com/uploads/1/3/1/3/131398110/2270435.pdf
    • http://files.professorwillis.com/uploads/1/3/0/9/130969819/3536095.pdf
    • http://mapuredax.anamcarafolkmusic.com/uploads/1/3/0/7/130739616/wajezojose.pdf
    • https://cdn.shopify.com/s/files/1/0433/0654/9406/files/70491609969.pdf
    • https://cdn.shopify.com/s/files/1/0434/5780/6502/files/35768537858.pdf
    • https://cdn.shopify.com/s/files/1/0428/2449/9367/files/joxuka.pdf
    • https://cdn.shopify.com/s/files/1/0439/2147/3691/files/69492612337.pdf
    • https://cdn.shopify.com/s/files/1/0432/7079/9510/files/26409942319.pdf
    • https://cdn.shopify.com/s/files/1/0435/2992/8863/files/fajar.pdf
    • https://cdn.shopify.com/s/files/1/0435/3084/6363/files/98374575195.pdf
    • https://cdn.shopify.com/s/files/1/0429/8620/9443/files/algorithm_analysis_and_design_mcq_with_answers.pdf
    • https://cdn.shopify.com/s/files/1/0443/1210/1020/files/dell_poweredge_r730_specs.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000726c.bin
edfbde0c015aa3ad7a15abef09ecf362df0b501221a88c5eff14a3de3092f3f2
pdf-font-stream PDF embedded font (sfnt) at offset 0x726C 5304 bytes
font_01_sfnt_off0000845b.bin
f0e6e36f5d2f3a4710350eb3d6e2132b806e491e03618bb1bc3aa8c986b2a0b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x845B 10312 bytes
font_02_sfnt_off0000a77c.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0xA77C 4324 bytes