Malicious PDF — malware analysis report

Static analysis result for SHA-256 6637e79dd0a57b9e…

MALICIOUS

PDF

47.8 KB Created: 2020-08-31 06:27:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ac11bc9c9e1ff9f6bcddde533513ce33 SHA-1: e8899a49aed152293342886f57f1ca582b5a1871 SHA-256: 6637e79dd0a57b9eae93ef0d196ddb2d4fea65ae7514f9a21bd42573af6e6313
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to a redirector service. The primary malicious URL identified is 'https://ttraff.com/wix?keyword=moto+g6+play', which is flagged as malicious. The document body, though heavily obfuscated, also contains this URL, suggesting it is the intended destination for users who interact with the document. The presence of numerous links to external PDFs, many hosted on Shopify, indicates a link farm or SEO poisoning tactic to distribute malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=moto+g6+play
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0433/7732/8286/files/niwak.pdf
    • https://cdn.shopify.com/s/files/1/0438/1235/6253/files/fitunaxerevusefofedowumi.pdf
    • https://cdn.shopify.com/s/files/1/0431/8425/9231/files/21607932938.pdf
    • https://cdn.shopify.com/s/files/1/0436/4409/2566/files/cryptography_and_network_security_by.pdf
    • https://cdn.shopify.com/s/files/1/0436/5336/5910/files/25089916659.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/dojezurin.pdf
    • https://static.usrfiles.com/ugd/66c878_16f5e7a6e4f749fda121b197d5121f62.pdf
    • https://static.usrfiles.com/ugd/b7082a_d419f2a5a02d49ad81cc40636931031e.pdf
    • https://static.usrfiles.com/ugd/b8c837_7aad1a7d4d234b7d821a4e902bbc6bbb.pdf
    • https://static.usrfiles.com/ugd/9e41f0_96d6f80d63ed4372bae7cda8f9c851d3.pdf
    • https://cdn.shopify.com/s/files/1/0432/7469/8902/files/introductory_chemistry_study_guide_answers.pdf
    • https://cdn.shopify.com/s/files/1/0434/0531/2154/files/napowifaja.pdf
    • https://cdn.shopify.com/s/files/1/0434/5816/6949/files/absolute_advantage_trade_theory.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006033.bin
007b629fe232139baf9386f64af0925ca85e7c08b60b4d124a30adccfd46f435
pdf-font-stream PDF embedded font (sfnt) at offset 0x6033 4976 bytes
font_01_sfnt_off00007147.bin
9aeebb39ccbee947770780f9dc76bf4faa8280eea3c1a53473c802545de89638
pdf-font-stream PDF embedded font (sfnt) at offset 0x7147 13320 bytes
font_02_sfnt_off00009c7c.bin
c9557d91917e40dbb2ce09b7ef560a04a9a832ffe2ebcac6b50408a58351272e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C7C 16092 bytes