Malicious PDF — malware analysis report

Static analysis result for SHA-256 543634d3f63bf267…

MALICIOUS

PDF

40.8 KB Created: 2020-09-18 07:13:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0855ac8134bc8899e22318fe5d29671d SHA-1: 0b1dede834629292cb607ea9079bf50d52acc571 SHA-256: 543634d3f63bf267552b72a6c3aac4ee009b7bfa085dbcf96da86ff02520d0ba
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains multiple embedded links, with one specifically pointing to a known malicious redirector. The document body, though heavily obfuscated, contains the URL 'https://ttraff.club/wix?keyword=friction+of+distance+geography' and a list of other PDF URLs, indicating a link farm or redirection attempt. The ML classifier also strongly flagged this PDF as malicious. The primary attack pattern involves luring the user to click on these malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=friction+of+distance+geography
    • http://kusolepes.conbeersfarm.com/uploads/1/3/1/4/131453465/lotunes.pdf
    • http://files.cninc.org/uploads/1/3/2/7/132740479/5324237.pdf
    • http://vabixiw.edasa.org/uploads/1/3/2/6/132682156/9951028.pdf
    • http://files.heritage-therapy.com/uploads/1/3/2/6/132683357/satifilak.pdf
    • http://files.georgesweeneyarchitect.com/uploads/1/3/1/8/131856569/sabusadezipe.pdf
    • http://jumede.honeybugscornwall.co.uk/uploads/1/3/0/7/130776007/jorakesavejobulezu.pdf
    • https://716e4417-8066-4c2f-9474-a03562c259d5.filesusr.com/ugd/a91264_b4460e1409e446899f4f1aad67a774bb.pdf?index=true
    • https://92d8a0d6-5847-43ad-ab58-7e5139cdd328.filesusr.com/ugd/8e7730_3cfb1cd4434143eb9c34678d60fa6878.pdf?index=true
    • https://eb057830-1e72-4738-bc90-3aa6a861bc76.filesusr.com/ugd/804ff6_9756ff6a55694dadb56c098862d2d2dc.pdf?index=true
    • https://f073cea6-abc3-4575-8efb-e9d8834fae64.filesusr.com/ugd/85d67f_4d8431033bc14141abfbeb485c04bd1d.pdf?index=true
    • https://61785856-4600-4b4f-8652-e1a18426917d.filesusr.com/ugd/008a9f_093865c2e3b9469ca5cc6768e9c592e1.pdf?index=true
    • https://c0c3a845-40c8-4634-a42a-596fc0f7bdb7.filesusr.com/ugd/12dc78_9fbfb623fac340ab8bf9a31340a556b5.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006135.bin
d1536769bdaec5faf09fc104b11fafe4f669e8afc151a22b2a858f9ec3980b31
pdf-font-stream PDF embedded font (sfnt) at offset 0x6135 5444 bytes
font_01_sfnt_off000073c1.bin
4b19627215d02b9335eec94e6178ebaace9d3d9be95b34233a7b622e2795293c
pdf-font-stream PDF embedded font (sfnt) at offset 0x73C1 10300 bytes