Malicious PDF — malware analysis report

Static analysis result for SHA-256 4dc7d6ee64e68268…

MALICIOUS

PDF

42.2 KB Created: 2020-08-04 09:50:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 33e17ea5a58f976a24f55e53d6654456 SHA-1: fdd72fba8543642f3df99420c203fe15a66aaccf SHA-256: 4dc7d6ee64e6826806302178f43f2c7d9333f6093dcd1801f70330fee1a2416b
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, many of which point to a link farm hosted on Shopify. One of the primary URLs, 'https://ttraff.cc/pify?keyword=allardyce+nicoll+british+drama+pdf', is identified as a malicious redirector. This suggests the document's purpose is to lure users into clicking these links, which then likely redirect to malicious websites for phishing or malware distribution. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=allardyce+nicoll+british+drama+pdf
    • http://files.aileenfletcher.com/uploads/1/3/1/6/131606262/xetizogeka_didaxu.pdf
    • http://files.oasystec.com/uploads/1/3/2/7/132710783/bewibigipapeg.pdf
    • http://files.academyforsales.co.uk/uploads/1/3/2/6/132681351/98eecfd.pdf
    • https://cdn.shopify.com/s/files/1/0437/6097/6021/files/14618129676.pdf
    • https://cdn.shopify.com/s/files/1/0430/5272/8474/files/fusojiwumewavowin.pdf
    • https://cdn.shopify.com/s/files/1/0431/3664/7317/files/47149678348.pdf
    • https://cdn.shopify.com/s/files/1/0433/8181/7495/files/dugosabasuxuberuliki.pdf
    • https://cdn.shopify.com/s/files/1/0438/2218/6653/files/44332249243.pdf
    • https://cdn.shopify.com/s/files/1/0433/7487/0689/files/junarexa.pdf
    • https://cdn.shopify.com/s/files/1/0432/7905/7056/files/46143039954.pdf
    • https://cdn.shopify.com/s/files/1/0430/6753/9623/files/14125066852.pdf
    • https://cdn.shopify.com/s/files/1/0430/3601/6802/files/accra_technical_university.pdf
    • https://cdn.shopify.com/s/files/1/0434/8634/7417/files/canulas_nasales.pdf
    • https://cdn.shopify.com/s/files/1/0431/5119/6314/files/pomalekisaf.pdf
    • https://cdn.shopify.com/s/files/1/0431/3631/9645/files/zevajosomazamefitubemenu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006689.bin
150d586926ed4d1e55411dd08a13dae04753585054a662f6a47eeec60db7bd6d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6689 5628 bytes
font_01_sfnt_off00007988.bin
73a544dab188ea2b95174154bf68726d3aea2e657201d31fbfc0f50c78f843dd
pdf-font-stream PDF embedded font (sfnt) at offset 0x7988 10120 bytes