Malicious PDF — malware analysis report

Static analysis result for SHA-256 0b5e13764da83e52…

MALICIOUS

PDF

91.1 KB Created: 2020-08-15 18:14:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0192cc0bd648f4da23050b4f05b51b3c SHA-1: c3e1a727e6f5fd541001fd06117b366d97e21e45 SHA-256: 0b5e13764da83e52b2a11cf84c41246124ada25511a4a9ce6739dbb19e56149f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.com'. The document body, though heavily obfuscated, also contains this URL, suggesting it is the primary lure. The presence of numerous external PDF links, many pointing to Shopify, indicates a link farm strategy to obscure the malicious destination. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=rbse%20previous%20year%20question%20papers%20class%2010%20pdf
    • http://files.makikicommunitygarden.com/uploads/1/3/1/6/131606965/bununeka.pdf
    • http://files.drinkyourcarbs.com/uploads/1/3/1/4/131437333/gatasuxokowajerovew.pdf
    • http://files.orchardhillohha.com/uploads/1/3/1/4/131411411/784490.pdf
    • http://files.3haivhmoob.com/uploads/1/3/1/0/131071137/pinixoxaf.pdf
    • http://files.gracioushomeandgifts.com/uploads/1/3/2/8/132816036/kasuxinanewune.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0437/8705/9352/files/tigutimazaline.pdf
    • https://cdn.shopify.com/s/files/1/0432/4950/0315/files/wumokazabigokenilexo.pdf
    • https://cdn.shopify.com/s/files/1/0437/9816/7713/files/torrenting_rosetta_stone.pdf
    • https://cdn.shopify.com/s/files/1/0432/1758/4283/files/3263936618.pdf
    • https://cdn.shopify.com/s/files/1/0431/8186/7176/files/renograma_con_captopril.pdf
    • https://cdn.shopify.com/s/files/1/0437/5547/1002/files/73180387888.pdf
    • https://cdn.shopify.com/s/files/1/0437/0835/0615/files/mexiluvomudupegorota.pdf
    • https://cdn.shopify.com/s/files/1/0433/2044/3045/files/6494906246.pdf
    • https://cdn.shopify.com/s/files/1/0437/2883/0625/files/gepovoraboror.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/46552055365.pdf
    • https://cdn.shopify.com/s/files/1/0431/1823/1709/files/93922043057.pdf
    • https://cdn.shopify.com/s/files/1/0432/7368/3112/files/microbiology_of_biogas_production.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011dfb.bin
c06398a38eb28c419fad72c7350eb98ffa68e90a0b4a4ecfeb9372037885f3df
pdf-font-stream PDF embedded font (sfnt) at offset 0x11DFB 5780 bytes
font_01_sfnt_off000131c4.bin
eee39bc3e4bccb547beaeb8c61ae804b2cef85b6b19bc06b6918222f68cc3216
pdf-font-stream PDF embedded font (sfnt) at offset 0x131C4 14460 bytes