Malicious PDF — malware analysis report

Static analysis result for SHA-256 01139c020ead0ba1…

MALICIOUS

PDF

119.2 KB Created: 2020-08-18 17:09:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 30b32e6496fb15df21325465c3a414a8 SHA-1: fd150ca6ee5f5b90a81e0e41382b296e0a34cd13 SHA-256: 01139c020ead0ba1b7e190b7c2016f2ef0d4fd72e6a5ac70df4888f2f87515c9
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, many of which are hosted on shopify.com. The document body, though heavily obfuscated, contains the malicious URL, suggesting an attempt to lure the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=unchained+monk+archetypes+guide
    • http://files.mikevincentphotography.net/uploads/1/3/1/3/131383541/baruxubu_kevogun_zujamozesaxapi_vigevoluzoju.pdf
    • http://files.ctkfriendsofmusic.com/uploads/1/3/0/8/130814205/840616.pdf
    • http://fokuteg.arupakaai.com/uploads/1/3/2/7/132740892/cda7de05bf25426.pdf
    • http://files.keckmanagementroofing.com/uploads/1/3/0/9/130969220/4290785.pdf
    • http://files.tlopezmarrero.com/uploads/1/3/2/6/132696598/8093018.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0434/8788/7510/files/49728773207.pdf
    • https://cdn.shopify.com/s/files/1/0435/4100/4439/files/facebook_new_emoji.pdf
    • https://cdn.shopify.com/s/files/1/0429/8165/4679/files/carbetocina_farmacologia.pdf
    • https://cdn.shopify.com/s/files/1/0431/5830/6965/files/bawukurakixifubigim.pdf
    • https://cdn.shopify.com/s/files/1/0437/1120/1435/files/antrenmanla_geometri_2.pdf
    • https://cdn.shopify.com/s/files/1/0434/3365/6476/files/guitar_arpeggios_book.pdf
    • https://cdn.shopify.com/s/files/1/0435/8298/0259/files/pegawezuji.pdf
    • https://cdn.shopify.com/s/files/1/0435/8592/9375/files/tier_list_7._14.pdf
    • https://cdn.shopify.com/s/files/1/0430/7006/2754/files/kebivaxubarunajekevakov.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018c49.bin
899862e8e19338467a22f7a02b9efba023b42fa9c85fb49e5666e831b4992736
pdf-font-stream PDF embedded font (sfnt) at offset 0x18C49 5496 bytes
font_01_sfnt_off00019ec4.bin
dd10e81b2034ddc46f0be0ae61f3cf629105d423ec188696794283ee07cf9b85
pdf-font-stream PDF embedded font (sfnt) at offset 0x19EC4 10136 bytes
font_02_sfnt_off0001c179.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C179 4324 bytes