Malicious PDF — malware analysis report

Static analysis result for SHA-256 6428e3a8efaacd42…

MALICIOUS

PDF

47.0 KB Created: 2020-08-04 07:09:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9e3a826dd00e57f27b0d0d082dc5bf34 SHA-1: 05eed85fdb65696909095f92e0dfc93ab506f04a SHA-256: 6428e3a8efaacd42cd3199f6b8c5045050fd2b1f2b76f2e11e26393463c0c89e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm with numerous embedded URLs, one of which, 'https://ttraff.ru/pify?keyword=101+ccna+labs+with+solutions+pdf', is flagged as a malicious redirector. The document body, though heavily obfuscated, contains this same URL, suggesting the primary purpose is to redirect users to malicious infrastructure. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=101+ccna+labs+with+solutions+pdf
    • http://files.digitall.photography/uploads/1/3/0/9/130969755/05a6a377e6.pdf
    • http://files.tomslawnandtreecare.com/uploads/1/3/1/0/131071145/1021154.pdf
    • http://files.greetingscomrade.com/uploads/1/3/0/7/130739746/d370ca.pdf
    • http://files.celiagaertig.com/uploads/1/3/2/3/132302978/mugulipiwa.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.opentle.org
    • https://cdn.shopify.com/s/files/1/0435/3848/1320/files/57130443173.pdf
    • https://cdn.shopify.com/s/files/1/0435/2563/6248/files/65356167522.pdf
    • https://cdn.shopify.com/s/files/1/0429/8883/0873/files/22257555071.pdf
    • https://cdn.shopify.com/s/files/1/0437/8142/3262/files/35847595404.pdf
    • https://cdn.shopify.com/s/files/1/0431/3910/4930/files/53972834741.pdf
    • https://cdn.shopify.com/s/files/1/0427/8360/4903/files/89415329809.pdf
    • https://cdn.shopify.com/s/files/1/0431/1583/9645/files/51250306526.pdf
    • https://cdn.shopify.com/s/files/1/0435/0138/7936/files/13219323718.pdf
    • https://cdn.shopify.com/s/files/1/0431/2114/8061/files/velosanubivoxad.pdf
    • https://cdn.shopify.com/s/files/1/0437/4292/0865/files/jennifer_saunders_holding_out_for_a_hero.pdf
    • https://cdn.shopify.com/s/files/1/0431/7229/8913/files/69776101961.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005eec.bin
f0588ead4cb1388cd5c11c23e158ff6cd6bd4fb39bec6b70e329010e238865c2
pdf-font-stream PDF embedded font (sfnt) at offset 0x5EEC 5476 bytes
font_01_sfnt_off0000718b.bin
3cae7bb82f733aea0a9e5faa904d9ef6439abe7b5a7271e2dfd450e98dee1bea
pdf-font-stream PDF embedded font (sfnt) at offset 0x718B 8744 bytes
font_02_sfnt_off00008a06.bin
2dc35dda0422af0ac1ffc0aa22964411d09c16ec04c3f0037c695a49aab76f7c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A06 11220 bytes