Malicious PDF — malware analysis report

Static analysis result for SHA-256 06bd76427472ac88…

MALICIOUS

PDF

82.9 KB Created: 2020-07-30 05:55:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 21271ee4369f683e3964998a43a1a148 SHA-1: 2fd198d15b1e74b461a0bdf83a4f5918f66bb405 SHA-256: 06bd76427472ac88c921525f6cf0e86dbc32c152739fb9d1547d2523d1ec619c
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many pointing to Shopify domains, suggesting a link farm or SEO manipulation tactic. One critical heuristic identified a link to known malicious redirector infrastructure at 'ttraff.ru'. The document body, though heavily obfuscated, contains keywords related to diet and PDF, aligning with the lure. No scripts were extracted, but the primary attack vector appears to be directing users to malicious URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=exocrine+pancreatic+insufficiency+diet+pdf
    • http://files.weisbeckerscholarshipfund.com/uploads/1/3/1/3/131398131/e58bcd3.pdf
    • http://files.maricelagutierrez.com/uploads/1/3/1/6/131637016/wuzat.pdf
    • http://files.ravenmiller.com/uploads/1/3/1/4/131437307/855104.pdf
    • http://files.ddoughty.com/uploads/1/3/2/6/132682646/186963aa.pdf
    • http://files.johanneimmis.com/uploads/1/3/0/9/130969837/nejadaviwab.pdf
    • http://fontawesome.iohttp://fontawesome.io/license/
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0432/0677/0849/files/79959562879.pdf
    • https://cdn.shopify.com/s/files/1/0430/7540/3936/files/23377087850.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/38935964995.pdf
    • https://cdn.shopify.com/s/files/1/0431/3733/5464/files/kutubikudusejez.pdf
    • https://cdn.shopify.com/s/files/1/0435/4624/7332/files/zavevog.pdf
    • https://cdn.shopify.com/s/files/1/0429/5308/0985/files/bogit.pdf
    • https://cdn.shopify.com/s/files/1/0437/2591/4262/files/78129186677.pdf
    • https://cdn.shopify.com/s/files/1/0432/7863/1072/files/mukujevada.pdf
    • https://cdn.shopify.com/s/files/1/0429/9273/0275/files/65759040064.pdf
    • https://cdn.shopify.com/s/files/1/0429/6628/6490/files/metigulor.pdf
    • https://cdn.shopify.com/s/files/1/0431/8104/7965/files/sewepupobipuvoluj.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb56.bin
1af1fdb02f150e4b7fb9ab825036f356033ef8d1f6adfeb519aebbff9637efeb
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB56 1724 bytes
font_01_sfnt_off0000f3e2.bin
4fb64f66851edcda84861bb611377981d9b752e5171e178fcfe0a4ba6d6b23cd
pdf-font-stream PDF embedded font (sfnt) at offset 0xF3E2 5128 bytes
font_02_sfnt_off00010560.bin
e8f02cdd08fde425f9e53787be8358fbbe819898762b257efdef55ea57018b8e
pdf-font-stream PDF embedded font (sfnt) at offset 0x10560 17532 bytes