Malicious PDF — malware analysis report

Static analysis result for SHA-256 596014f52cadcdfa…

MALICIOUS

PDF

50.9 KB Created: 2020-09-07 06:21:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: eecb598d331d0ee111733045a7504155 SHA-1: de8942c390e1613abc0481aa9ba731ec2a981317 SHA-256: 596014f52cadcdfacfbef1ec3df90fa34a3f030d11c6698ab516d6b3b75a5f49
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.me/pify?keyword=esma+guidelines+etfs+and+other+ucits+issues'. Additionally, another critical heuristic indicates a PDF link farm, suggesting an attempt to distribute malicious content or SEO spam. The ML classifier also strongly flagged this PDF as malicious. The document body, though partially corrupted, contains the same malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/pify?keyword=esma+guidelines+etfs+and+other+ucits+issues
    • https://cdn.shopify.com/s/files/1/0431/8593/0389/files/canzoniere_scout_fse.pdf
    • https://cdn.shopify.com/s/files/1/0433/4456/0281/files/anydesk_android_full_control.pdf
    • https://cdn.shopify.com/s/files/1/0432/4527/3248/files/the_art_of_graphic_design_bradbury_thompson.pdf
    • https://static.usrfiles.com/ugd/23b571_4a7ed6b3702e4aabb8277ebceede7391.pdf
    • https://static.usrfiles.com/ugd/a44510_2f33f05ac3664ca480a56d79304096a1.pdf
    • https://static.usrfiles.com/ugd/32777b_30dbaa1ba40d4a35a4e8d942a259fab6.pdf
    • https://static.usrfiles.com/ugd/0bfb20_34598be77833482098fe8cbb2f3c8cbf.pdf
    • https://cdn.shopify.com/s/files/1/0431/8828/9694/files/masewusomarewisu.pdf
    • https://cdn.shopify.com/s/files/1/0432/7401/0782/files/2497044785.pdf
    • https://cdn.shopify.com/s/files/1/0467/7510/7737/files/chrome_for_ubuntu_16._04_lts.pdf
    • https://cdn.shopify.com/s/files/1/0430/6921/0773/files/agenda_2030_portugues.pdf
    • https://cdn.shopify.com/s/files/1/0431/4539/6386/files/66817212072.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000079a2.bin
b3905f328f2e896962ae434469a17fa9291dfdf838e57a1d2ed9966a1a48fddc
pdf-font-stream PDF embedded font (sfnt) at offset 0x79A2 4728 bytes
font_01_sfnt_off00008a39.bin
29eddc2dcafbf36f40e26030334a922c2dff0b91b64ef9e03c3cb7c4241b1a1b
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A39 5392 bytes
font_02_sfnt_off00009c63.bin
a94f51947c57dcb8841584b0b318e9310234029030d98d60a7c311306695ee84
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C63 10028 bytes