Malicious PDF — malware analysis report

Static analysis result for SHA-256 dfc95fd5bcf9b6a1…

MALICIOUS

PDF

44.1 KB Created: 2020-08-19 17:26:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 125f7ece01d796e41642895b87de35ce SHA-1: dac72f3b392208ab429640dc176566bd392b28a4 SHA-256: dfc95fd5bcf9b6a1209d2152758343d043bef2a852b26b86dc3a3c62e949a362
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged as malicious by a machine learning classifier and contains a critical heuristic indicating it links to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains the URL that triggered the redirector heuristic. The presence of numerous external links, many pointing to Shopify domains, suggests a link farm intended to obscure the ultimate malicious destination.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=pathfinder+exploiter+wizard+guide
    • http://files.survivorthrivers.com/uploads/1/3/2/6/132683017/6340783.pdf
    • http://zifoj.ashbrookwindowfashions.com/uploads/1/3/0/9/130969140/gosokokanefig.pdf
    • https://cdn.shopify.com/s/files/1/0431/4287/3249/files/alcoholismo_en_adolescentes_causas_y_consecuencias.pdf
    • https://cdn.shopify.com/s/files/1/0438/6127/8885/files/muvadoji.pdf
    • https://cdn.shopify.com/s/files/1/0429/1851/0745/files/statistical_foundations_of_machine_learning.pdf
    • https://cdn.shopify.com/s/files/1/0429/9869/4049/files/65246374748.pdf
    • https://cdn.shopify.com/s/files/1/0431/2127/9138/files/xalem.pdf
    • https://cdn.shopify.com/s/files/1/0427/9838/3260/files/muguw.pdf
    • https://cdn.shopify.com/s/files/1/0428/1267/0111/files/dresser_drawer_guide_repair.pdf
    • https://cdn.shopify.com/s/files/1/0429/7955/7539/files/minopi.pdf
    • https://cdn.shopify.com/s/files/1/0430/5652/9565/files/hibbeler_dynamics_12th_edition_solutions_manual.pdf
    • https://cdn.shopify.com/s/files/1/0428/9059/2422/files/dungeon_master_s_guide_2_4e.pdf
    • https://cdn.shopify.com/s/files/1/0434/6413/0725/files/18305303204.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006e78.bin
b45d76b1aba7a86e2dfee2329ab870b48cd802a3c3521cb2c0d333ec65b56dc1
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E78 5336 bytes
font_01_sfnt_off000080b4.bin
b11e3410304d77452e6ceee288ede0a7611f490764e966b064d6ef7d98817946
pdf-font-stream PDF embedded font (sfnt) at offset 0x80B4 10164 bytes