Malicious PDF — malware analysis report

Static analysis result for SHA-256 0ce8ef47442f1983…

MALICIOUS

PDF

72.0 KB Created: 2020-08-29 21:08:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3975f5fd21958df5533553126ddc91f7 SHA-1: 3ee656933550fc417416d2525de409283951030d SHA-256: 0ce8ef47442f1983babf19cec4ae4c0119e911fa0c313f5c72a34f43a6edd36c
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=kakashi+and+minato'. Additionally, it exhibits a PDF link farm behavior with numerous external links. The document body, though heavily obfuscated, also contains the same malicious URL, suggesting an attempt to drive traffic to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=kakashi+and+minato
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/b8c837_3bd5f229bb2d4ace8ce9d91a1189196a.pdf
    • https://static.usrfiles.com/ugd/b8c837_4e2aacc39c9b4d2cb4a4ad025b9efbc1.pdf
    • https://static.usrfiles.com/ugd/b8c837_fd1238f0b46d4037a71f11897567eaff.pdf
    • https://cdn.shopify.com/s/files/1/0428/2351/6323/files/imperative_and_exclamatory_sentences_worksheets.pdf
    • https://cdn.shopify.com/s/files/1/0431/7547/7414/files/sobex.pdf
    • https://cdn.shopify.com/s/files/1/0453/4956/8667/files/callus_plant_tissue_culture.pdf
    • https://cdn.shopify.com/s/files/1/0427/8606/2495/files/after_effects_time_expression.pdf
    • https://cdn.shopify.com/s/files/1/0437/9394/0629/files/votisobirularigaz.pdf
    • https://static.usrfiles.com/ugd/b8c837_bbbfd0603f3e4887bbdb92b5c4ab1d31.pdf
    • https://static.usrfiles.com/ugd/b8c837_6addfa1903ca4b7481afaf82ee466e43.pdf
    • https://static.usrfiles.com/ugd/b8c837_b5fa2199f93440e990327209a7072f78.pdf
    • https://cdn.shopify.com/s/files/1/0434/8765/8141/files/36314786749.pdf
    • https://cdn.shopify.com/s/files/1/0431/3769/5895/files/ligesexed.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006a5d.bin
6621fadaf7b25fc5d2f7d06f42edbf625a695fa83eaf5680e81404532c60f1db
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A5D 38236 bytes
font_01_sfnt_off0000dfc4.bin
44644c6b619ba9f8831eacdef15af232ff29f5bc965c91c758fe0f34549bf236
pdf-font-stream PDF embedded font (sfnt) at offset 0xDFC4 4972 bytes
font_02_sfnt_off0000f074.bin
79e36f9ccbfa63e8db97d4c697d61ac385a9f711dfc8d7351ada2a5c5222fd7f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF074 10196 bytes