Malicious PDF — malware analysis report

Static analysis result for SHA-256 1662a6bfe5a603b1…

MALICIOUS

PDF

41.1 KB Created: 2020-08-06 15:35:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fd81d1ea8e6f1e5f3ece44da0aadd826 SHA-1: 6ce826bcfce69dea44071ac46abb8a142b28e076 SHA-256: 1662a6bfe5a603b156446166731f2de81c6367e43b1e09c74da41e04f6a7e881
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to external PDF files, suggesting a link farm or SEO manipulation tactic. One critical heuristic identified a link to known malicious redirector infrastructure, specifically 'ttraff.com', which is used to disguise the ultimate destination. The document body, though heavily obfuscated, contains the same malicious URL, indicating an attempt to lure the user into clicking it.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=definition+of+mass+communication+by+different+authors+pdf
    • http://files.abbyvasek.com/uploads/1/3/0/8/130874667/9057367.pdf
    • http://kemosal.thedentalsmilecentre.com/uploads/1/3/1/3/131380429/nufijufetifajozazazu.pdf
    • http://files.personalspaceproject.com/uploads/1/3/2/7/132740343/piwepapefa-kavijabojexopi-fuwuwumewa.pdf
    • http://files.richpmurphy.uk/uploads/1/3/0/8/130814042/zesefotul.pdf
    • http://piwevad.tateliberaswanson.com/uploads/1/3/0/7/130775387/dovemoxosurak.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0437/6556/3549/files/pifonavefibutejasejad.pdf
    • https://cdn.shopify.com/s/files/1/0432/9360/6046/files/round_avery_labels.pdf
    • https://cdn.shopify.com/s/files/1/0437/0844/8922/files/sports_card_price_guide.pdf
    • https://cdn.shopify.com/s/files/1/0437/6874/2040/files/mick_goodrick.pdf
    • https://cdn.shopify.com/s/files/1/0428/0533/0083/files/gebezipipovigewelesog.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/89186344985.pdf
    • https://cdn.shopify.com/s/files/1/0434/1678/0956/files/preschool_classroom_management_150_teacher_tested_techniques.pdf
    • https://cdn.shopify.com/s/files/1/0431/2530/9604/files/37781590596.pdf
    • https://cdn.shopify.com/s/files/1/0431/5506/2938/files/51448862763.pdf
    • https://cdn.shopify.com/s/files/1/0431/9445/0078/files/how_to_update_chrome.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/rinavupomun.pdf
    • https://cdn.shopify.com/s/files/1/0437/9040/1687/files/65645591747.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000616d.bin
4b61ec3edb7efda5d5dfcf16469a04a0ebb069923bfa8af2caf7c7ae2ab3b555
pdf-font-stream PDF embedded font (sfnt) at offset 0x616D 5604 bytes
font_01_sfnt_off00007459.bin
80f686602f5a4264146858c5a7b4bb4fe2d7a14a93240d74661505990ac67cd7
pdf-font-stream PDF embedded font (sfnt) at offset 0x7459 10112 bytes