Malicious PDF — malware analysis report

Static analysis result for SHA-256 60d3c7429da16b82…

MALICIOUS

PDF

119.8 KB Created: 2020-08-24 21:28:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9fbb54d1808e3c4516db15028b4625b0 SHA-1: cf08af3a6ecb2f70bd6866e0a5b224a7b4570e94 SHA-256: 60d3c7429da16b82c45ab89d078f983f3897b25ecee59089f7982bb1d079af06
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link to a known malicious redirector, ttraff.com, which is designed to lead users to further malicious content. The document body, though heavily obfuscated, contains the same URL, suggesting an attempt to disguise the malicious link under a seemingly benign topic related to 'sofa foam sheet'. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=sofa+foam+sheet+near+me
    • http://files.allamericanhousesitters.com/uploads/1/3/2/6/132682119/3698369.pdf
    • http://files.friendsofthemeadows.org/uploads/1/3/1/8/131871602/9464717.pdf
    • http://files.granvillegaps.org/uploads/1/3/1/6/131607440/6171617.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://cdn.shopify.com/s/files/1/0439/1727/9400/files/xotawunawusoxubegobovogaw.pdf
    • https://cdn.shopify.com/s/files/1/0462/7477/3152/files/cv_template_uk_personal_statement.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/juzopuzenafososokazulu.pdf
    • https://cdn.shopify.com/s/files/1/0427/7813/2636/files/ruwuvomimop.pdf
    • https://cdn.shopify.com/s/files/1/0432/2259/7796/files/wojokezegulogixap.pdf
    • https://cdn.shopify.com/s/files/1/0431/5702/9024/files/wedding_invitation_card_ai_template.pdf
    • https://cdn.shopify.com/s/files/1/0433/5576/6942/files/xutopovagefidojuvotos.pdf
    • https://cdn.shopify.com/s/files/1/0436/6660/4182/files/vox_ac30_schematic.pdf
    • https://cdn.shopify.com/s/files/1/0428/2925/0719/files/jeziwubinof.pdf
    • https://cdn.shopify.com/s/files/1/0434/8972/2534/files/graphene_oxide_sheets.pdf
    • https://cdn.shopify.com/s/files/1/0430/2913/5521/files/arbitration_act_1996_bare_act.pdf
    • https://cdn.shopify.com/s/files/1/0433/0723/7531/files/xaragabafanifi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001850d.bin
95b3bf9b07b7f0680e8f76111c47d1a1b0fea187780fe132d7e8f24179613506
pdf-font-stream PDF embedded font (sfnt) at offset 0x1850D 5080 bytes
font_01_sfnt_off00019629.bin
8535adde27ff4fef22669046e807f62f0784ff24ada901d510e21bd35bf75284
pdf-font-stream PDF embedded font (sfnt) at offset 0x19629 15676 bytes
font_02_sfnt_off0001c67d.bin
8e84c18d84911d32c5e056c771a9491fa773314f1e76147bff929c79c86b0a9c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C67D 2692 bytes