Malicious PDF — malware analysis report

Static analysis result for SHA-256 4169bbd4df4dbfed…

MALICIOUS

PDF

44.8 KB Created: 2020-08-14 10:26:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 18b47d50dae69ce6d69456196d567ef7 SHA-1: 59a74566379c590eae657e59e50368d350633ec0 SHA-256: 4169bbd4df4dbfed6b605ad073103a59882390d00687115ac5cb6476b6d04e20
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to a redirector service (ttraff.com). The document body text and embedded links are disguised as academic worksheets, likely to lure users into clicking the malicious links. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=7.+3+triangle+inequalities+worksheet+answers
    • http://remitodan.atholtonmusic.org/uploads/1/3/1/4/131406149/wosasakusexet_zodawuwapeve.pdf
    • http://files.alexherrald.com/uploads/1/3/1/3/131381518/juvoxelazo-gadex-vilukiwe.pdf
    • http://files.singersandactorsworkshop.com/uploads/1/3/2/7/132740218/mubazaxumadajag.pdf
    • http://files.planet-patrick.com/uploads/1/3/1/4/131437930/9716647.pdf
    • https://cdn.shopify.com/s/files/1/0434/1461/8262/files/tomezudulunuwojasapef.pdf
    • https://cdn.shopify.com/s/files/1/0429/9954/6010/files/2514038694.pdf
    • https://cdn.shopify.com/s/files/1/0432/2256/5032/files/mevazosisira.pdf
    • https://cdn.shopify.com/s/files/1/0434/6642/4470/files/62723553396.pdf
    • https://cdn.shopify.com/s/files/1/0430/0659/1127/files/12629262762.pdf
    • https://cdn.shopify.com/s/files/1/0437/3286/1079/files/carry_on_lelivros.pdf
    • https://cdn.shopify.com/s/files/1/0431/8144/1181/files/41385550926.pdf
    • https://cdn.shopify.com/s/files/1/0434/7576/3353/files/gulilizuxufo.pdf
    • https://cdn.shopify.com/s/files/1/0433/3341/9160/files/bonitaporifon.pdf
    • https://cdn.shopify.com/s/files/1/0435/4428/1247/files/36497079084.pdf
    • https://cdn.shopify.com/s/files/1/0431/9179/5875/files/reverse_an_integer_java.pdf
    • https://cdn.shopify.com/s/files/1/0437/0006/0310/files/361465106.pdf
    • https://cdn.shopify.com/s/files/1/0433/6576/1176/files/84421659572.pdf
    • https://cdn.shopify.com/s/files/1/0436/4291/2926/files/bologna_process_higher_education.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005adc.bin
87932074d2dbbae793b2ba78463017c516b0a1ed21ab56b8cb0bab1a4ea21c65
pdf-font-stream PDF embedded font (sfnt) at offset 0x5ADC 5408 bytes
font_01_sfnt_off00006d4e.bin
3ce606ee526b86aa3e450024fc88c03cfebf20bcf207c47a9577a53268adce3a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D4E 10172 bytes
font_02_sfnt_off00009047.bin
2cc36779403287548c184605c5d9ac9f8e39fd5c9622849292a4135ce18498ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x9047 16208 bytes