Malicious PDF — malware analysis report

Static analysis result for SHA-256 6aa04e5ed46ce02e…

MALICIOUS

PDF

81.0 KB Created: 2020-08-22 14:51:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a0ceaf7735177572ed0e9b2a0be5c9d6 SHA-1: ffbb4a8eedcd10aa849f5c19a23ff379f9d29181 SHA-256: 6aa04e5ed46ce02ee3b86d90f74a2b4a5e41cc6d034aaeefaf4504985725b502
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link to a known malicious redirector, ttraff.com, which is likely intended to lead the user to a malicious site. The document also exhibits characteristics of a link farm, with numerous embedded links to external PDFs, suggesting an attempt to manipulate search engine results or distribute further malicious content. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9950

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=form+utility+meaning+in+telugu
    • http://files.stmarysofthelakeff.com/uploads/1/3/0/7/130739419/neralivodup.pdf
    • http://files.goodharborpottery.com/uploads/1/3/1/3/131379860/zotox.pdf
    • http://files.alogcabininthewoods.com/uploads/1/3/0/9/130969791/sixotetilofim-viburo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102Hussain
    • http://smc.org.inhttp://smc.org.in
    • http://www.indictrans.org
    • https://cdn.shopify.com/s/files/1/0432/8597/1110/files/diwegowu.pdf
    • https://cdn.shopify.com/s/files/1/0437/0923/5353/files/competitor_analysis_template_ppt.pdf
    • https://cdn.shopify.com/s/files/1/0438/9113/0536/files/13209273695.pdf
    • https://cdn.shopify.com/s/files/1/0433/4744/3865/files/fibotolenemufitekesogemin.pdf
    • https://cdn.shopify.com/s/files/1/0434/5679/0695/files/history_of_allopathy.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/13170590630.pdf
    • https://cdn.shopify.com/s/files/1/0431/5280/1943/files/speak_english_like_an_american_idioms.pdf
    • https://cdn.shopify.com/s/files/1/0431/1557/7504/files/heart_attack_heart_attack_movie_songs.pdf
    • https://cdn.shopify.com/s/files/1/0434/7474/7558/files/omr_answer_sheet_100.pdf
    • https://cdn.shopify.com/s/files/1/0433/4062/8120/files/kedup.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • https://gitlab.com/smc/meera/blob/master/COPYING
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005fa2.bin
0c355c03036bfe584609e63ab2a4f2967642f6a6a028ce2425b81676c189feeb
pdf-font-stream PDF embedded font (sfnt) at offset 0x5FA2 4884 bytes
font_01_sfnt_off00007032.bin
ff8289fcab20b7b81f5dc7c47458689637225d7099c48932a46d6898d6123f6c
pdf-font-stream PDF embedded font (sfnt) at offset 0x7032 2656 bytes
font_02_sfnt_off00007b37.bin
623f3dc160466080235b5d69e2cc70c9e2e99ef737c273ede0d3d2ca18f3e99e
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B37 6040 bytes
font_03_sfnt_off00008ebe.bin
b5c6b6e0c9ada0bf1c6b02372d38a6194b0fc304f51b15768a03b7bd417def48
pdf-font-stream PDF embedded font (sfnt) at offset 0x8EBE 3048 bytes
font_04_sfnt_off00009acd.bin
18b250f24057ce91e4a59b25c1eec79fa8b4d7e2cb9f6c0de02c7e032a072fd4
pdf-font-stream PDF embedded font (sfnt) at offset 0x9ACD 2328 bytes
font_05_sfnt_off0000a582.bin
1699ca17824c51a5b327f4fa57af6be450c73cfe5903018555e03ee7e343484b
pdf-font-stream PDF embedded font (sfnt) at offset 0xA582 7680 bytes
font_06_sfnt_off0000bdd3.bin
5fd53e2058c4f5d98b70161d670f1e42036942552fef68ac845a5e47e2d7f715
pdf-font-stream PDF embedded font (sfnt) at offset 0xBDD3 2604 bytes
font_07_sfnt_off0000c8f3.bin
87016e8933cc862d1d188edfbee698abcff8178ed3d6b510b61737ee02f60284
pdf-font-stream PDF embedded font (sfnt) at offset 0xC8F3 4336 bytes
font_08_sfnt_off0000d694.bin
e651c18d791c6074c403165c9572e2d4e7ac58a8a85e0e4393e0e59ffb5bc10f
pdf-font-stream PDF embedded font (sfnt) at offset 0xD694 10720 bytes
font_09_sfnt_off0000fad5.bin
fe8d29fb9280ea3870b9c0bd4732e2c5922f7a0dee8ee31e30e1e2453b0b70a9
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAD5 17100 bytes
font_10_sfnt_off000113d2.bin
cd703102b342fc07840eb8de18edd1f8b45b49f504a4f2dfaaa01ebbd649021d
pdf-font-stream PDF embedded font (sfnt) at offset 0x113D2 5580 bytes
font_11_sfnt_off000127bb.bin
89aa5ef39ecd647c310fa7d43209dd0d208a608e38381102f2e40635d4f29b56
pdf-font-stream PDF embedded font (sfnt) at offset 0x127BB 2608 bytes