Malicious PDF — malware analysis report

Static analysis result for SHA-256 01571066d13e97ff…

MALICIOUS

PDF

53.1 KB Created: 2020-09-23 01:15:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2507f7ffa9b0890644f781e75ab6f105 SHA-1: 8defe1d058d8babac20aedeebe24d8746b4ce95c SHA-256: 01571066d13e97ff3dee4691219caae7ba0689a05ec7653ec7728d6f85859979
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious Link

This PDF file contains numerous embedded links, with a critical heuristic firing indicating a link to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains a URL that appears to be a lure for 'exam answers'. The primary malicious URL identified is https://ttraff.me/wix?keyword=comp-xm+final+exam+answers, which is likely used to redirect the user to a malicious site or download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=comp-xm+final+exam+answers
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://3376ebd6-150f-42ba-9cfe-07949ee07b77.filesusr.com/ugd/041b56_adacccf6abd74ba28d40a84fb949e225.pdf?index=true
    • https://4d9796a5-42f3-4340-bd51-03d511ba0752.filesusr.com/ugd/ef0078_01df36086a194470bd49bea6e222d4a0.pdf?index=true
    • https://ea76cc2b-fa3e-452c-acf4-469a97052c41.filesusr.com/ugd/a107db_0f2a96b937ef47569c3fa06d9f8404ac.pdf?index=true
    • https://8db53268-8144-4f19-80df-8dbe05d838ae.filesusr.com/ugd/115d6e_0cfd994334e94940997debe2015813d9.pdf?index=true
    • https://8444730b-cb12-47a9-a4b5-8276ebf54aeb.filesusr.com/ugd/1479de_c98bf0465d1d40fd81a74a9d78e3189c.pdf?index=true
    • https://e691f9ea-5d19-43fb-af0a-e29deec8f2d9.filesusr.com/ugd/c6ac46_b9c65f67fc484932943158e0782ed108.pdf?index=true
    • https://c1fa507c-c15e-4b15-bfb6-8971a04503b3.filesusr.com/ugd/ab0441_77d1cb641ed544109fab72a5475e8683.pdf?index=true
    • https://5642cdb3-bac3-4892-9e7d-24d56f6ee904.filesusr.com/ugd/851c7c_bb363320bf984faa9269f3dfa3a50f86.pdf?index=true
    • https://f3470d16-fb16-4685-b8d9-d0bc29c888c2.filesusr.com/ugd/ff3115_478c55e09051467c9177c0276c9992ab.pdf?index=true
    • https://3f92c016-5275-4f9b-af9d-368d91823cb9.filesusr.com/ugd/33a2e4_45998c440bbe46d68745d3cb40e9291d.pdf?index=true
    • https://d2e7916c-9702-4ced-b061-fe0d64a63cab.filesusr.com/ugd/e4a001_0227ce2aac064d3db70695d9d0bc377c.pdf?index=true
    • https://93f5fc1a-7988-47fb-ad43-8296291671c5.filesusr.com/ugd/3fd21f_aa89ef70b615458288a91414e9d1c9d6.pdf?index=true
    • https://51f3cac3-1404-4319-99cd-c8f60f6bc8c4.filesusr.com/ugd/e2c223_2ee6547919a74e779fbafa8737f33091.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0438/6498/1664/files/blood_pressure_normal_range.pdf
    • https://cdn.shopify.com/s/files/1/0434/7291/2549/files/65391280751.pdf
    • https://cdn.shopify.com/s/files/1/0432/8374/2884/files/viribimijasaget.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008432.bin
a2d2f6dd6ba07f1154cfd09f31276dfed81b0f23d233ec4860fbc6d7622fc08e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8432 4968 bytes
font_01_sfnt_off00009513.bin
0f46047dbc873646d5ceb76ee53b850565692cad93d92a35ac17522db0c31f87
pdf-font-stream PDF embedded font (sfnt) at offset 0x9513 10560 bytes
font_02_sfnt_off0000b932.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0xB932 4324 bytes