Malicious PDF — malware analysis report

Static analysis result for SHA-256 186d0c873918fd7c…

MALICIOUS

PDF

52.6 KB Created: 2020-08-31 02:29:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 01ae6295c7f797e11b0af020eddcffc5 SHA-1: 2fd527801d3a50cc39e724c822d4e1af428946f2 SHA-256: 186d0c873918fd7cc73134dc552dfbb8d723d5a4a51359c11a03da3c2b948de6
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a heuristic firing for linking to known malicious redirector infrastructure, specifically 'ttraff.link'. It also exhibits characteristics of a PDF link farm, embedding numerous URLs, many of which point to benign content but are likely used to mask the malicious redirector. The document body, though heavily obfuscated, contains the malicious redirector URL and appears to be a lure related to 'alturas de un triangulo equilatero'. The primary malicious IOC is the redirector URL, which likely leads to further malicious content or exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=alturas+de+un+triangulo+equilatero
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/a298ce_ea1445e6cfcf4ffeb51c2d208fde2534.pdf
    • https://static.usrfiles.com/ugd/b8c837_3ba1575a95e042ae8e625d3dd533067c.pdf
    • https://static.usrfiles.com/ugd/b8c837_84925f555f054e87bcf7bacf60537fb1.pdf
    • https://static.usrfiles.com/ugd/912de2_807f48bcd3f34d329105a010aa5eb14f.pdf
    • https://static.usrfiles.com/ugd/b8c837_675826b6c0e14a5c887689b8dad0a5f5.pdf
    • https://static.usrfiles.com/ugd/98e298_235f06f8ecf746d8aa0344bc6e5f85fc.pdf
    • https://cdn.shopify.com/s/files/1/0429/4865/7318/files/wovugijev.pdf
    • https://cdn.shopify.com/s/files/1/0431/5417/8216/files/tetorik.pdf
    • https://cdn.shopify.com/s/files/1/0441/0051/8040/files/xobotonalimilupebebedozop.pdf
    • https://cdn.shopify.com/s/files/1/0434/8038/3653/files/jexarapag.pdf
    • https://cdn.shopify.com/s/files/1/0433/3443/4969/files/79414436690.pdf
    • https://cdn.shopify.com/s/files/1/0429/1500/4582/files/site_reliability_engineering_o_reilly.pdf
    • https://cdn.shopify.com/s/files/1/0436/0706/4734/files/jquery_ajax_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0430/1042/4985/files/jironivuzamepewidijelok.pdf
    • https://cdn.shopify.com/s/files/1/0429/7841/0655/files/kesukusugapelenekewiboj.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000067e8.bin
edf517a561ed5132c6c1d5718ac6ff9d870a00e6f43a91762fd168a2279cca75
pdf-font-stream PDF embedded font (sfnt) at offset 0x67E8 6440 bytes
font_01_sfnt_off000077de.bin
9f1a2e1dd3449a5d7328d6bcd5099d333cd4750e28cd2e329afa14d8438a6514
pdf-font-stream PDF embedded font (sfnt) at offset 0x77DE 5108 bytes
font_02_sfnt_off00008935.bin
af00ced304df664b5ebfffd990c7f9700ad8741badfee8a5bd3b22387c217bf3
pdf-font-stream PDF embedded font (sfnt) at offset 0x8935 11364 bytes
font_03_sfnt_off0000ae6a.bin
3c1c7bd747a9a8f6e1c531457064e9378d9a893e5271ac7381d9d0015290d8f4
pdf-font-stream PDF embedded font (sfnt) at offset 0xAE6A 16088 bytes