Malicious PDF — malware analysis report

Static analysis result for SHA-256 4bc90dcc3c95f15d…

MALICIOUS

PDF

41.9 KB Created: 2020-08-14 23:27:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 34b19f37049a4c8bba71dd224950f1e4 SHA-1: 184ce35ffe676354fdd6d0fa28f2ccfe4215b9ee SHA-256: 4bc90dcc3c95f15ded3d8d229acb4ed90294024db62ebf5db74b7ca125b4a308
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to a link farm hosted on Shopify. One of these links, "ttraff.ru", is identified as a malicious redirector. The document body, though obfuscated, contains the "Baby shark dance challenge" lure and the malicious redirector URL, suggesting an attempt to drive traffic to malicious sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=baby+shark+dance+challenge
    • http://files.jenniferhainesmua.com/uploads/1/3/2/6/132682905/zuzudenewafe-nopatid-toxuvodujunak.pdf
    • http://files.vegantshirts.ca/uploads/1/3/0/8/130873708/jirogol.pdf
    • http://files.ariaisa.com/uploads/1/3/1/3/131398251/modove-nupasudes-menusakuwenodu.pdf
    • https://cdn.shopify.com/s/files/1/0429/4865/7318/files/mamikinovewezotakevaxej.pdf
    • https://cdn.shopify.com/s/files/1/0431/5725/8401/files/jeopardy_online_test_answers_2019.pdf
    • https://cdn.shopify.com/s/files/1/0428/6208/4262/files/bibliothque_du_quebec.pdf
    • https://cdn.shopify.com/s/files/1/0432/4704/2715/files/arlena_witt.pdf
    • https://cdn.shopify.com/s/files/1/0429/0579/6774/files/64351196583.pdf
    • https://cdn.shopify.com/s/files/1/0437/7578/7169/files/national_geographic_book_of_animal_poetry.pdf
    • https://cdn.shopify.com/s/files/1/0432/9183/6566/files/45459527130.pdf
    • https://cdn.shopify.com/s/files/1/0430/9919/3501/files/bajureretupoxulo.pdf
    • https://cdn.shopify.com/s/files/1/0432/8508/6374/files/sokavupidu.pdf
    • https://cdn.shopify.com/s/files/1/0432/5959/2864/files/13086094754.pdf
    • https://cdn.shopify.com/s/files/1/0440/7836/6885/files/5664049180.pdf
    • https://cdn.shopify.com/s/files/1/0435/4709/9290/files/cds_ota_syllabus_2020.pdf
    • https://cdn.shopify.com/s/files/1/0429/8512/8095/files/aac_to_mp3_converter.pdf
    • https://cdn.shopify.com/s/files/1/0437/3174/6967/files/90994202996.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004f2f.bin
20e8c7a151c6523207e89ae8fecb30f57e61af5060ed8955a0bc59fefe2374c5
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F2F 5556 bytes
font_01_sfnt_off000061ff.bin
8a4242c4175f9c5c6c299dc7de30ac76bff8a3416bbcd5f442404fd0a0e39efc
pdf-font-stream PDF embedded font (sfnt) at offset 0x61FF 10140 bytes
font_02_sfnt_off000084f4.bin
e51faea2bfde0b17a9a6f109d4ac083881df923a7eac87b4a8f0b27ed5b3183d
pdf-font-stream PDF embedded font (sfnt) at offset 0x84F4 16312 bytes