Malicious PDF — malware analysis report

Static analysis result for SHA-256 15d5da6f9a96a52c…

MALICIOUS

PDF

46.8 KB Created: 2020-08-10 10:51:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8fcfd5ba12ddcf40e065eda1c7ced8d8 SHA-1: f353ad338d2e30f1e43c88fd17e0623cf9a50b07 SHA-256: 15d5da6f9a96a52c2896fb17f0df7dce54fc8012cfef1fb635484fd7fad077a0
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, with the primary link directing to a known malicious redirector at 'ttraff.com'. The document body text and embedded links suggest a lure related to fitness exercises, likely to trick users into clicking the malicious URL. The ML classifier strongly indicated maliciousness, and the PDF structure itself contained numerous external links, characteristic of SEO spam or link farm tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=100+bodyweight+exercises+pdf
    • http://files.fincast.com.au/uploads/1/3/2/8/132815872/tujawil_sopanesubudak_xapuxolavemoziz_kuzebenunimumi.pdf
    • http://files.jointheteam.saintleoresidencelife.com/uploads/1/3/0/7/130740521/kabezenuki.pdf
    • http://files.conesintheharbor.com/uploads/1/3/1/4/131406527/0284054491d2c5a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0433/9430/2117/files/61480210365.pdf
    • https://cdn.shopify.com/s/files/1/0431/4365/9677/files/addictions_a_banquet_in_the_grave_free.pdf
    • https://cdn.shopify.com/s/files/1/0432/6614/6472/files/88314654882.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/45560821546.pdf
    • https://cdn.shopify.com/s/files/1/0434/3123/1644/files/applications_of_gold_nanoparticles_in_cancer_nanotechnology.pdf
    • https://cdn.shopify.com/s/files/1/0435/6187/7663/files/stopping_by_woods_on_a_snowy_evening_appreciation.pdf
    • https://cdn.shopify.com/s/files/1/0433/4845/9675/files/tanijavurodonarumuniz.pdf
    • https://cdn.shopify.com/s/files/1/0432/5205/6227/files/wujiverojuxobazadati.pdf
    • https://cdn.shopify.com/s/files/1/0430/0737/7561/files/juzat.pdf
    • https://cdn.shopify.com/s/files/1/0430/9401/6157/files/65992568543.pdf
    • https://cdn.shopify.com/s/files/1/0427/8845/4559/files/35206639428.pdf
    • https://cdn.shopify.com/s/files/1/0430/8919/9268/files/belajar_hukum_tajwid.pdf
    • https://cdn.shopify.com/s/files/1/0432/1142/3902/files/54059984895.pdf
    • https://cdn.shopify.com/s/files/1/0428/6113/3990/files/58075280543.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007892.bin
54a6102c311523fff5ada84c1bb8094b0a8b67ee329fe1fb89c108002c1cb3ea
pdf-font-stream PDF embedded font (sfnt) at offset 0x7892 5676 bytes
font_01_sfnt_off00008c01.bin
5d6e3f562b11605660ba443f7cdc4a4df6c779649c31710dbcc492425a363e5f
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C01 10096 bytes