Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f4e7710132a760c…

MALICIOUS

PDF

47.3 KB Created: 2020-08-21 06:16:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cdb182af9ee3f43da81e37b50ad253c3 SHA-1: 3b1fbbe58066bebfa9d79f3ac09c59d2869ba8a9 SHA-256: 4f4e7710132a760cc82bf0211657d56f43b8b41c62f0a0b70bb74221040cc48f
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified as a 'PDF SEO Link Farm'. One of these links, 'https://ttraff.ru/pify?keyword=fitted+sheet+over+flat+sheet', is flagged as a known malicious redirector. The document body, though heavily obfuscated, contains the same URL, suggesting it is the primary lure. The ML classifier strongly indicated maliciousness, supporting the heuristic findings.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=fitted+sheet+over+flat+sheet
    • http://jekuk.baltimoremineralsociety.org/uploads/1/3/0/7/130739967/63ce90.pdf
    • http://jumon.majesticdjbooth.com/uploads/1/3/1/4/131406063/7490400.pdf
    • https://cdn.shopify.com/s/files/1/0432/0762/2824/files/73478765724.pdf
    • https://cdn.shopify.com/s/files/1/0433/9384/3358/files/easy_english_story_books_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/46552055365.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/duwaxufezemurogagur.pdf
    • https://cdn.shopify.com/s/files/1/0433/8722/4214/files/gutanomezunu.pdf
    • https://cdn.shopify.com/s/files/1/0439/4100/3432/files/environmental_monitoring_and_analytical_techniques.pdf
    • https://cdn.shopify.com/s/files/1/0430/7465/0261/files/xaxeta.pdf
    • https://cdn.shopify.com/s/files/1/0430/1737/1797/files/zekikuzaxu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000066e6.bin
e8c7ab501b1c19bd1643451bc3b763ec3c7caa694ec63fd1f9c839f8f2ce978b
pdf-font-stream PDF embedded font (sfnt) at offset 0x66E6 5012 bytes
font_01_sfnt_off000077f1.bin
d6831f9b495f8e371db8b62c037a176b4ffa55d43079953653df9bf5b5196a3f
pdf-font-stream PDF embedded font (sfnt) at offset 0x77F1 10120 bytes
font_02_sfnt_off00009ad4.bin
ed45a24507f18daeaf6b6e9cac20235e9e43bed88bc2d44b7621eff085e31190
pdf-font-stream PDF embedded font (sfnt) at offset 0x9AD4 16344 bytes