Malicious PDF — malware analysis report

Static analysis result for SHA-256 12805bc46e6d8a39…

MALICIOUS

PDF

48.4 KB Created: 2020-09-01 21:49:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b5e94371587f662aaf4b687c0220382d SHA-1: 1658abeeb6ee106f86637f1a080cbbfca6881163 SHA-256: 12805bc46e6d8a395179ef2b45c79f921d2565fae2ce751e40a2bc6edde7d16e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, ttraff.me, which is likely used to obscure the final malicious destination. The document also contains a large number of links to other PDFs, suggesting it is part of a link farm or SEO manipulation scheme. While no scripts were explicitly extracted, the PDF structure and embedded links are indicative of malicious intent, potentially leading to further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=factores+bioticos+y+abioticos+ejemplos+pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://static.usrfiles.com/ugd/89c6ad_1c55b097ad3f4ee6ac454e8c050a3176.pdf
    • https://static.usrfiles.com/ugd/b8c837_4d0dcc6942254291ad08b1dd63b43c85.pdf
    • https://static.usrfiles.com/ugd/15ebe2_fbf6ef0d1b764d5da0b92a78e281da16.pdf
    • https://static.usrfiles.com/ugd/3ce946_932dfdf47abc4766832eec94479b6c75.pdf
    • https://cdn.shopify.com/s/files/1/0459/7248/8359/files/96494689214.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/nozawilod.pdf
    • https://cdn.shopify.com/s/files/1/0434/9925/8022/files/bacteria_spore.pdf
    • https://cdn.shopify.com/s/files/1/0448/2557/5581/files/hygienic_design_of_food_processing_equipment.pdf
    • https://static.usrfiles.com/ugd/b8c837_2f3eccaf156e4af7859294b9918a49ba.pdf
    • https://static.usrfiles.com/ugd/6f58fb_e250e02814df479689cc43e486b43ac9.pdf
    • https://static.usrfiles.com/ugd/c3548c_b32b51cc97794aad9f01d0aa9f01d361.pdf
    • https://static.usrfiles.com/ugd/d5415a_99d5d76ac20541a39e934b420e41b45c.pdf
    • https://static.usrfiles.com/ugd/3e87bf_aedf9f2e2c5444508fb91bd3e231f721.pdf
    • https://static.usrfiles.com/ugd/1ee69b_dfc0bdd0ecb940bba2f647ec1fd763dd.pdf
    • https://static.usrfiles.com/ugd/538d67_89319156b6564100b18f19cd475fe5d5.pdf
    • https://static.usrfiles.com/ugd/6f53d7_6c10f85bd3b34cc1a0bd062f6521be84.pdf
    • https://static.usrfiles.com/ugd/61804c_c6730f2fa6aa44be8f99fcb92f9c88c6.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007006.bin
b09cd9b1164b4946fc2c83d4222a8e041ab13b249b9ed311fd0d144f4645ec11
pdf-font-stream PDF embedded font (sfnt) at offset 0x7006 5256 bytes
font_01_sfnt_off000081ee.bin
594f2abc825a693748fa2a33df149d666e193d064b5a034a6726bf5d329ea48b
pdf-font-stream PDF embedded font (sfnt) at offset 0x81EE 10700 bytes
font_02_sfnt_off0000a4c0.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0xA4C0 4324 bytes