Malicious PDF — malware analysis report

Static analysis result for SHA-256 d00868725d92d828…

MALICIOUS

PDF

43.5 KB Created: 2020-08-30 20:46:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 25ed4b4777b9e1fcec32caed8c6df746 SHA-1: a458c0e01e8fff2b381c8afba7ad456b482ae192 SHA-256: d00868725d92d82830b1e5ef541e90898ba04cbb3047ad98d60a8db73f789c2b
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged as malicious by a machine learning classifier and contains a critical heuristic firing for a malicious redirector link. The document body, though heavily obfuscated, contains the URL that triggered the malicious redirector heuristic. This suggests the primary purpose of the PDF is to lure users to the malicious URL, which is likely a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=eldritch+invocations+5e+guide
    • https://cdn.shopify.com/s/files/1/0437/7640/9751/files/97253208535.pdf
    • https://cdn.shopify.com/s/files/1/0436/1424/0931/files/tardis_blueprints_and_parts_list.pdf
    • https://cdn.shopify.com/s/files/1/0432/1725/6603/files/spartan_bar_bending_machine_manual.pdf
    • https://cdn.shopify.com/s/files/1/0429/2355/7030/files/gewaxuvubaxurikejawu.pdf
    • https://cdn.shopify.com/s/files/1/0431/8383/3249/files/31042459091.pdf
    • https://static.usrfiles.com/ugd/3f80ec_1ea30c44add2450988091d491292b41a.pdf
    • https://static.usrfiles.com/ugd/51c472_2f4c7847e6244c97a51de2dc384dd599.pdf
    • https://static.usrfiles.com/ugd/b444d4_df3bc4dd9e1d402c90333e49e0f24ab6.pdf
    • https://static.usrfiles.com/ugd/b0b521_7a46a0a2b43741989b77a2ef9f2a9202.pdf
    • https://static.usrfiles.com/ugd/b8c837_24f40ae37c9043b6b7bc1a45d3cb2a28.pdf
    • https://static.usrfiles.com/ugd/b8c837_7b096c093df247f990f3b43c424a6382.pdf
    • https://static.usrfiles.com/ugd/bf650e_5fd6481f6ff7405c87f0bf7909fdff90.pdf
    • https://static.usrfiles.com/ugd/b8c837_67869d0b1a424653b7b6877be0e9f2df.pdf
    • https://static.usrfiles.com/ugd/4b68be_b6bfcfcb56894b0a87fbb72348e7a59b.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ccc.bin
8ea34572be73c5ad85b7ea7f4b9beaeb829365a6a481cf6e288b30e80dc9a9b4
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CCC 5344 bytes
font_01_sfnt_off00007eec.bin
c65dbb269bea36499b3312e30a08d5b1f3ea301e87ac913d41155811ffd01263
pdf-font-stream PDF embedded font (sfnt) at offset 0x7EEC 10104 bytes