Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f1117083e7cb897…

MALICIOUS

PDF

54.2 KB Created: 2020-08-05 02:18:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 157ac98d4a60e318116d46c448f74803 SHA-1: 1bf9227108e27955f99137886472d0c9b8fa38fd SHA-256: 2f1117083e7cb897d6076865b5ff8037880a907e53c98caa9ee4e50f40bb0d19
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm with numerous embedded URLs, including a critical redirector link to 'ttraff.com'. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains the primary malicious URL, suggesting the intent is to lure the user to a compromised site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=alphabet+grec+ancien+pdf
    • http://files.tdabelew.com/uploads/1/3/1/6/131636965/zukiz-fexaziwanal.pdf
    • http://files.indianlakechurch.org/uploads/1/3/1/3/131382590/ratosiwuralaxoroseb.pdf
    • http://files.elizabethowens.com/uploads/1/3/2/8/132814086/pixobaw_mobipevubogokab.pdf
    • http://files.ledge-island-gallery.com/uploads/1/3/2/6/132682090/1097289.pdf
    • https://cdn.shopify.com/s/files/1/0434/0521/3847/files/riwumenitenokod.pdf
    • https://cdn.shopify.com/s/files/1/0431/4519/9777/files/22052560537.pdf
    • https://cdn.shopify.com/s/files/1/0432/0365/7887/files/sweet_sixteen_lyric.pdf
    • https://cdn.shopify.com/s/files/1/0431/0866/3456/files/97904585732.pdf
    • https://cdn.shopify.com/s/files/1/0440/2964/0854/files/2009_volkswagen_tiguan_owners_manual.pdf
    • https://cdn.shopify.com/s/files/1/0436/2056/5156/files/76731136431.pdf
    • https://cdn.shopify.com/s/files/1/0430/7946/7162/files/pharmacy_technician_practice_test_2015.pdf
    • https://cdn.shopify.com/s/files/1/0433/6749/7880/files/5582457261.pdf
    • https://cdn.shopify.com/s/files/1/0439/0119/0299/files/salifowexijalixadofi.pdf
    • https://cdn.shopify.com/s/files/1/0430/3477/1610/files/photoshop_calligraphy_brush.pdf
    • https://cdn.shopify.com/s/files/1/0431/6640/0663/files/guvedireto.pdf
    • https://cdn.shopify.com/s/files/1/0433/7002/1014/files/lekir.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006094.bin
4d369e807a92625527f5912ac08ed96d8d11e0ce267c501aae6e113a505d9628
pdf-font-stream PDF embedded font (sfnt) at offset 0x6094 5368 bytes
font_01_sfnt_off000072d0.bin
335a3b6a3e50a326430a7a89e4daea9c547b8563f48cf859c3a5cdec4c851a03
pdf-font-stream PDF embedded font (sfnt) at offset 0x72D0 26172 bytes
font_02_sfnt_off0000b4fe.bin
9c3eb3ba841afbb2c7b7d5baf4008ce6163893a9c689772c792c8d86fd0bdfb4
pdf-font-stream PDF embedded font (sfnt) at offset 0xB4FE 16220 bytes