Malicious PDF — malware analysis report

Static analysis result for SHA-256 15cde697f4ffe6d3…

MALICIOUS

PDF

44.3 KB Created: 2020-08-29 06:26:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a0dc1c7f1b5a1c4ddf9b90c71c87ac30 SHA-1: 400ae428d5266c7ab45ed0e4f80a1da9fa606adf SHA-256: 15cde697f4ffe6d3268625e65732c4f8862e190511bc21da3a0c19afc9e23692
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains embedded links that point to a known malicious redirector, ttraff.com. The document body, though heavily obfuscated, contains text that appears to be a lure related to 'Pathfinder hellfire' and mentions 'compact pdf', aligning with the heuristic findings. The presence of numerous external PDF links suggests an attempt to obscure the ultimate destination or engage in link farming, further supporting malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=pathfinder+hellfire+compact+pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://static.usrfiles.com/ugd/b8c837_8378728c69bd48c3a7473999f5506312.pdf
    • https://static.usrfiles.com/ugd/b8c837_6cc8e483236b4629a2d83a1a97a25f86.pdf
    • https://static.usrfiles.com/ugd/b8c837_794924bd2501441fa6219088ae1e30bc.pdf
    • https://static.usrfiles.com/ugd/b8c837_a60104e521124fb1bae5ac2a736543af.pdf
    • https://static.usrfiles.com/ugd/b8c837_b5394b67b6eb420ba181c0e7eca91549.pdf
    • https://static.usrfiles.com/ugd/b8c837_e279ad5ada5a4ffcb3250b435ef5c171.pdf
    • https://cdn.shopify.com/s/files/1/0436/4346/9974/files/90102220982.pdf
    • https://cdn.shopify.com/s/files/1/0434/7065/1542/files/wetamelavibuwuv.pdf
    • https://cdn.shopify.com/s/files/1/0437/4138/0759/files/illustrator_marketing_templates.pdf
    • https://cdn.shopify.com/s/files/1/0428/3554/2182/files/divopisugutowufezigu.pdf
    • https://cdn.shopify.com/s/files/1/0458/1071/2742/files/cap_bdu_uniform_regulations.pdf
    • https://cdn.shopify.com/s/files/1/0432/0188/8416/files/xulijowagazuboduk.pdf
    • https://cdn.shopify.com/s/files/1/0429/9273/0275/files/14025394585.pdf
    • https://cdn.shopify.com/s/files/1/0431/1613/4562/files/convert_to_word_adobe_pro.pdf
    • https://cdn.shopify.com/s/files/1/0438/9660/2779/files/bhp_billiton_annual_report_2011.pdf
    • https://cdn.shopify.com/s/files/1/0429/2080/4518/files/mukarovalazol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000060c9.bin
8ecfac3cfd0877fc5ad589dc88b8ef213ce2d95ac1c3eb55a784cd050b9112f6
pdf-font-stream PDF embedded font (sfnt) at offset 0x60C9 5004 bytes
font_01_sfnt_off00007189.bin
69813c7a988160bcb6e37054590d9a25abb3bb7ebe16a059d7069639bf01d78f
pdf-font-stream PDF embedded font (sfnt) at offset 0x7189 10848 bytes
font_02_sfnt_off000095ed.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x95ED 4324 bytes