Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f577675c29aa002…

MALICIOUS

PDF

32.8 KB Created: 2020-08-15 22:30:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ec772fed82110ba25b42ae6d4c6cb85f SHA-1: 128ccc7f80be4b5ad50e0501e7a36377bfe6f5de SHA-256: 3f577675c29aa002263ee2a95e4a952c62995b75eadb5603f0fb06b766d74dcd
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

This PDF document contains a significant number of embedded links, many of which point to external PDF files, indicating a link farm for SEO poisoning. One critical heuristic identified a link to a known malicious redirector, ttraff.com, which is likely the primary malicious payload delivery mechanism. The document body, though heavily obfuscated, contains references to 'Hoffmann group katalog pdf' and the tool 'wkhtmltopdf', suggesting a lure to disguise malicious links as legitimate catalog downloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=hoffmann%20group%20katalog%20pdf
    • http://files.cambodianorchid.com/uploads/1/3/0/8/130813373/399860.pdf
    • https://cdn.shopify.com/s/files/1/0435/2750/4031/files/lotosusegezixi.pdf
    • https://cdn.shopify.com/s/files/1/0432/2865/9870/files/joligodefesepowurofor.pdf
    • https://cdn.shopify.com/s/files/1/0433/4324/9576/files/ergonomic_handle_design.pdf
    • https://cdn.shopify.com/s/files/1/0432/8954/2809/files/pipozatebufozunosozapirax.pdf
    • https://cdn.shopify.com/s/files/1/0437/4986/7681/files/organized_crime_11th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0432/0896/6307/files/48001408403.pdf
    • https://cdn.shopify.com/s/files/1/0434/1510/9799/files/19389361529.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000041f8.bin
d234d6ca99dda0ecd183beae7edbaab824d2bb22fda20aa736c54e7ae7dd6090
pdf-font-stream PDF embedded font (sfnt) at offset 0x41F8 5208 bytes
font_01_sfnt_off00005396.bin
637f18efef6e69d9a36fa75db355c1f62b3609806906bc9f612a85995fa35eda
pdf-font-stream PDF embedded font (sfnt) at offset 0x5396 10404 bytes