Malicious PDF — malware analysis report

Static analysis result for SHA-256 008e470a25f8431e…

MALICIOUS

PDF

39.8 KB Created: 2020-08-09 13:45:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d90be414046b5ea621714ba2ea200c48 SHA-1: 72d4806f7e0d4a06c45f6a5f19b9badf4ee27313 SHA-256: 008e470a25f8431e07297b94ddd6c2aa043a5608e70c51c55e5c5183ab6da379
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous links, with one specifically pointing to a known malicious redirector infrastructure at 'ttraff.com'. The ML classifier strongly indicated maliciousness, and the presence of a link farm suggests an attempt to distribute malicious content or engage in phishing. No scripts were extracted, but the primary attack vector appears to be the embedded malicious URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=arithmetic+series+exercises+pdf
    • http://files.lshbooks.com/uploads/1/3/1/6/131637658/093a7498e2ab11f.pdf
    • http://files.tinezrootsclub.com/uploads/1/3/1/3/131384573/6723058.pdf
    • http://novedo.toris-pinkribbonjourney.co.uk/uploads/1/3/2/6/132696111/489945e.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0438/0013/3793/files/como_convertir_un_archivo_java_a_ejecutable.pdf
    • https://cdn.shopify.com/s/files/1/0428/8148/2919/files/23650656803.pdf
    • https://cdn.shopify.com/s/files/1/0437/1791/8875/files/adventure_time_season_10_episode_12.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/89965927340.pdf
    • https://cdn.shopify.com/s/files/1/0430/1216/1685/files/space_wolves_7th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0429/9204/2137/files/mufizamatasomuxemesonan.pdf
    • https://cdn.shopify.com/s/files/1/0433/1061/2635/files/wetudowufewulinozepiju.pdf
    • https://cdn.shopify.com/s/files/1/0437/3407/3505/files/jebogowemugumosit.pdf
    • https://cdn.shopify.com/s/files/1/0440/7663/0181/files/calibre_convert_kindle_to.pdf
    • https://cdn.shopify.com/s/files/1/0432/9016/5403/files/flipping_table_emote.pdf
    • https://cdn.shopify.com/s/files/1/0437/6123/8168/files/zefifagajufive.pdf
    • https://cdn.shopify.com/s/files/1/0433/8191/5802/files/89633282632.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005d44.bin
6f4401afb9634d42141e04d6e43c4a724c3d63e8ef62d0d7f01965527820a152
pdf-font-stream PDF embedded font (sfnt) at offset 0x5D44 5208 bytes
font_01_sfnt_off00006eda.bin
e7e8a793dce9c2e980add08917bcc0ab93e25c7a6d5652cdfc00be83530d1be3
pdf-font-stream PDF embedded font (sfnt) at offset 0x6EDA 10504 bytes