Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f0a36e77689aa0b…

MALICIOUS

PDF

42.0 KB Created: 2020-09-01 02:09:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b4923e95117707c14bc20b0dcbc8e48d SHA-1: fd9d72d3188e95b68bafb42d3a673473970a2774 SHA-256: 0f0a36e77689aa0ba9c5e342a03501755670b6e76385d2c5bb95cdaa9fb2bb77
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to a link farm designed to generate traffic. One prominent URL, https://ttraff.cc/wix?keyword=aptitude+questions+in+tamil, is identified as a malicious redirector. The document body, though heavily obfuscated, contains references to this URL and other PDF links, suggesting a social engineering attempt to drive traffic to malicious infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=aptitude+questions+in+tamil
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/de3d83_a4d4e0175d574d63afc19e1beff90bad.pdf
    • https://static.usrfiles.com/ugd/72216b_2474c98668e748f0b912240531fdce41.pdf
    • https://static.usrfiles.com/ugd/b8c837_cfcda2e4e5bd4a3d8b7503cf0da89f99.pdf
    • https://static.usrfiles.com/ugd/d17951_a4fa99b226194802a393b1f92578c9f2.pdf
    • https://static.usrfiles.com/ugd/03ae60_a7891b015fe84d9f9cd742062b610b26.pdf
    • https://static.usrfiles.com/ugd/b28561_e74f1ff5c72e442db033858a08ba3680.pdf
    • https://static.usrfiles.com/ugd/b8c837_2a7ab4fa13ef4a3381c92a1aa9ddd512.pdf
    • https://static.usrfiles.com/ugd/590778_8424268b6a094ee1a4bc5998d8a0f06e.pdf
    • https://static.usrfiles.com/ugd/b8c837_f602e6d0c98f4ab48961cb3c154c89d3.pdf
    • https://static.usrfiles.com/ugd/cc15ef_5ad89f4b864946bea0df2a90cb0cd856.pdf
    • https://static.usrfiles.com/ugd/b8c837_6be614b22c3548e18788740c7ce0d049.pdf
    • https://static.usrfiles.com/ugd/de60da_a37c409ce6d943d89c79053dd281d3e9.pdf
    • https://static.usrfiles.com/ugd/bb13a2_f33ad82418e4467ba32731b09fe3aff7.pdf
    • https://static.usrfiles.com/ugd/c8a981_bfc46e4db266483782e4cf9d2cc77455.pdf
    • https://static.usrfiles.com/ugd/cafc24_136a05a70c7942db9b2ad10e04bff249.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006624.bin
07af2bb2c0528577b8b472a037da646a3dc48ba8e643c21461640322422802ba
pdf-font-stream PDF embedded font (sfnt) at offset 0x6624 5124 bytes
font_01_sfnt_off0000777f.bin
5b6b17d21cddbb84ac7913952e582e1600ebcea024ae79c8479a558ce048a582
pdf-font-stream PDF embedded font (sfnt) at offset 0x777F 10648 bytes