Malicious PDF — malware analysis report

Static analysis result for SHA-256 074d97d803553a9e…

MALICIOUS

PDF

47.9 KB Created: 2020-08-04 08:19:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5df7ac9590c3af1233707b029e6c1a51 SHA-1: 360801c470a5606c5915c7de7d4f112560826cdf SHA-256: 074d97d803553a9e455398d85794be891ef1db371a1e426d7583b0a666daf39b
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, with the primary URL `https://ttraff.com/pify?keyword=ernest+renan+averroes+pdf` identified as a malicious redirector. The ML classifier also strongly indicated maliciousness. This suggests the document is designed to lure users to malicious sites, likely for phishing or to download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=ernest+renan+averroes+pdf
    • http://files.creativelyyourscustomcakes.com/uploads/1/3/0/8/130874254/16c439de0da.pdf
    • http://files.breakingfreeky.org/uploads/1/3/1/3/131381976/mexibasoje.pdf
    • http://wimogiv.fireangelphotography.net/uploads/1/3/0/9/130969723/duserivikererir-jesipezovinorog.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0432/0156/0737/files/7312313173.pdf
    • https://cdn.shopify.com/s/files/1/0435/6843/1265/files/35999454318.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/67641838088.pdf
    • https://cdn.shopify.com/s/files/1/0427/8976/5279/files/kigudonotoxovexomuvineb.pdf
    • https://cdn.shopify.com/s/files/1/0429/6966/1589/files/velifer.pdf
    • https://cdn.shopify.com/s/files/1/0431/1816/6167/files/zusegiwilukikizovijuj.pdf
    • https://cdn.shopify.com/s/files/1/0428/9763/7535/files/topinuxolobo.pdf
    • https://cdn.shopify.com/s/files/1/0433/1739/5614/files/milaxemimanakesibujebod.pdf
    • https://cdn.shopify.com/s/files/1/0437/8404/4705/files/metallica_fade_to_black_mp3.pdf
    • https://cdn.shopify.com/s/files/1/0430/6203/4589/files/mumizebepolavik.pdf
    • https://cdn.shopify.com/s/files/1/0430/7543/6698/files/71092979819.pdf
    • https://cdn.shopify.com/s/files/1/0432/7899/1520/files/tixisuvevunujaboli.pdf
    • https://cdn.shopify.com/s/files/1/0429/8365/3535/files/dimejoziril.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007f04.bin
312d684b97c12fc0f20d3d38972dcfdcec343a1dac63f5228db4828a47a22cbc
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F04 5020 bytes
font_01_sfnt_off00009033.bin
d627f62548c089a5205c39b7de09aee841776ffd89eeaa3d7607b85fe7f75978
pdf-font-stream PDF embedded font (sfnt) at offset 0x9033 10080 bytes