Malicious PDF — malware analysis report

Static analysis result for SHA-256 04f3bddc1dc2ea97…

MALICIOUS

PDF

44.4 KB Created: 2020-09-10 23:12:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cbe071f7b63907004254b1411ebad5ad SHA-1: 1d31df645708182118271de1d72b9617b15e4f83 SHA-256: 04f3bddc1dc2ea977d5db0b010580a50a606fddee5a8af8d1ca6963519fc8117
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains embedded URLs that redirect to malicious infrastructure, masquerading as a meeting agenda. The primary malicious URL, 'https://ttraff.club/wix?keyword=weekly+manager+meeting+agenda+template', is flagged as a malicious redirector. The document also exhibits characteristics of a link farm, with numerous external PDF links, many of which point to Shopify domains, suggesting an attempt to manipulate search engine results or distribute content. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=weekly+manager+meeting+agenda+template
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0431/7167/6314/files/12820700756.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/nimapudusakodinufuzexive.pdf
    • https://cdn.shopify.com/s/files/1/0434/5328/4519/files/substr_in_c.pdf
    • https://cdn.shopify.com/s/files/1/0429/7320/0537/files/xijuribidodiw.pdf
    • https://static.usrfiles.com/ugd/f523c3_eb274c2a329845729ee367e036efce8c.pdf
    • https://static.usrfiles.com/ugd/e4a001_88c98cbdba014f95995ebd66af8abb22.pdf
    • https://static.usrfiles.com/ugd/dcbeda_196a2a6106b54f73bb1563c424f6a9ec.pdf
    • https://static.usrfiles.com/ugd/04c368_4c659b01e652449aaa39bbf06da653c2.pdf
    • https://static.usrfiles.com/ugd/b8c837_a890250f56a84113a07372589ff5293c.pdf
    • https://static.usrfiles.com/ugd/24deb6_a051c2715be94e38a562fb024225dcbc.pdf
    • https://static.usrfiles.com/ugd/6cf392_7a54b4d8dcb54845aef7051c251b35d1.pdf
    • https://cdn.shopify.com/s/files/1/0435/9674/2815/files/audit_report_example_icaew.pdf
    • https://cdn.shopify.com/s/files/1/0432/6726/0582/files/47288460635.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007059.bin
9a4069237d0e69a866fe9df30d4227e8d500c85e715e038115be703e3de28f78
pdf-font-stream PDF embedded font (sfnt) at offset 0x7059 5280 bytes
font_01_sfnt_off0000824e.bin
61cab9c129c1e5a001b3cbbbd16449a729ae592e4b7bee5db09098ec601259e2
pdf-font-stream PDF embedded font (sfnt) at offset 0x824E 10240 bytes