Malicious PDF — malware analysis report

Static analysis result for SHA-256 000195398de84449…

MALICIOUS

PDF

46.9 KB Created: 2020-08-12 06:47:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d9843e535b122a21666b0509dd5ecd59 SHA-1: c7cfd83ccc59804c669d7202afea371da5716e4f SHA-256: 000195398de84449e93569504e94ee340f6f07c103cdd6f388f4fe639f78c300
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a lure related to 'school leave application format' but is primarily a link farm. It embeds numerous URLs, including a critical redirector link to 'ttraff.cc', which is known malicious infrastructure. The ML classifier also strongly indicated maliciousness, supporting the conclusion that this PDF is designed to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=school+leave+application+format+in+english+pdf
    • http://files.jamesvandenburg.com/uploads/1/3/1/8/131857631/tixafot.pdf
    • http://tiganozoz.casperpecancompany.com/uploads/1/3/2/6/132696021/zidetimusozidalebo.pdf
    • http://files.taejulee.com/uploads/1/3/1/8/131872054/peguforafu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://cdn.shopify.com/s/files/1/0432/7420/7387/files/lozijazojafited.pdf
    • https://cdn.shopify.com/s/files/1/0429/9682/6273/files/defupasete.pdf
    • https://cdn.shopify.com/s/files/1/0440/9737/2312/files/nizafa.pdf
    • https://cdn.shopify.com/s/files/1/0436/7872/8345/files/bharatanatyam_mudras_with_meanings.pdf
    • https://cdn.shopify.com/s/files/1/0431/5122/9089/files/muluxinaguvolovogim.pdf
    • https://cdn.shopify.com/s/files/1/0434/7923/6760/files/regukezugaj.pdf
    • https://cdn.shopify.com/s/files/1/0440/6312/9765/files/63825103284.pdf
    • https://cdn.shopify.com/s/files/1/0434/7628/7648/files/favozuxonijo.pdf
    • https://cdn.shopify.com/s/files/1/0431/7482/2043/files/93171997084.pdf
    • https://cdn.shopify.com/s/files/1/0432/0795/0495/files/77764212357.pdf
    • https://cdn.shopify.com/s/files/1/0433/6045/2760/files/80668619793.pdf
    • https://cdn.shopify.com/s/files/1/0430/6750/6841/files/telufizizipaba.pdf
    • https://cdn.shopify.com/s/files/1/0431/0571/4338/files/83761696912.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000068dc.bin
125554395084603e2f000c4b1fb54156331059eb3e88e691418bab6d8924dc51
pdf-font-stream PDF embedded font (sfnt) at offset 0x68DC 5732 bytes
font_01_sfnt_off00007c38.bin
cade02b3a23de8b7d75fbd5d64a78db58d7dfdccd9c8310d4b1d9a942713192e
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C38 10332 bytes
font_02_sfnt_off00009fa3.bin
3b5ed5cb494b39b87a3020261a75edb3d2afffb507de0d4216e6a54fca7bde38
pdf-font-stream PDF embedded font (sfnt) at offset 0x9FA3 3748 bytes