Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c3ab76dafe196d3…

MALICIOUS

PDF

74.1 KB Created: 2020-08-01 09:34:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a2d9c7997ffbe6beed34630c57e3c66e SHA-1: 166cfd6488be4a10789f8b0e2056f44d0c7f2899 SHA-256: 6c3ab76dafe196d3130afa6c279d11357f5d6ef47eac8767aa2eb78329004dc7
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file contains embedded links, one of which, 'https://ttraff.cc/pify?keyword=what+does+adv+stand+for', is flagged as a malicious redirector. The document body, though heavily obfuscated, also contains this URL, suggesting an attempt to lure the user to malicious infrastructure. The presence of numerous other PDF links, many hosted on Shopify, indicates a potential link farm or SEO manipulation tactic to distribute malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9957

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=what+does+adv+stand+for
    • http://files.westcoastjen.com/uploads/1/3/1/6/131606111/9902366.pdf
    • http://files.marinwoodturningandcompany.com/uploads/1/3/1/4/131454521/ratikoxujoberu.pdf
    • http://files.alanbirtwistle.com/uploads/1/3/1/3/131383664/werox_xapedewero_bemidituziv_zurer.pdf
    • http://files.ikmchauffeurs.com/uploads/1/3/1/4/131407089/6c3fd143ee88.pdf
    • http://files.happiervalley.com/uploads/1/3/1/4/131408954/7697838.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://www.opentle.org
    • https://cdn.shopify.com/s/files/1/0433/5131/0488/files/8976324337.pdf
    • https://cdn.shopify.com/s/files/1/0437/4996/5978/files/fesodeferikudu.pdf
    • https://cdn.shopify.com/s/files/1/0436/5379/1909/files/diner_dash_flo_on_the_go.pdf
    • https://cdn.shopify.com/s/files/1/0430/3205/1873/files/55094289515.pdf
    • https://cdn.shopify.com/s/files/1/0435/6728/4379/files/tijagefipaniredal.pdf
    • https://cdn.shopify.com/s/files/1/0427/9874/3719/files/1121715546.pdf
    • https://cdn.shopify.com/s/files/1/0431/7950/7870/files/70169867674.pdf
    • https://cdn.shopify.com/s/files/1/0437/2886/3397/files/nilodopib.pdf
    • https://cdn.shopify.com/s/files/1/0429/8443/9971/files/61632596774.pdf
    • https://cdn.shopify.com/s/files/1/0434/8103/9013/files/36441708849.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/mekokagowofulagifofid.pdf
    • https://cdn.shopify.com/s/files/1/0435/5804/3807/files/fipapujawaloriz.pdf
    • https://cdn.shopify.com/s/files/1/0434/0809/7445/files/vemog.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/ferenap.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_011_off0000ee5e.bin
9a53eb0f5d899206140142024e1329928d04523b9b037af6ea44b3d64dff0b7c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xEE5E 18176 bytes
font_00_sfnt_off00006bd9.bin
8dd18ea3225c9156ee85a36fa04e9c099c7a096be51c4f08e18fd5a20beb4544
pdf-font-stream PDF embedded font (sfnt) at offset 0x6BD9 6320 bytes
font_01_sfnt_off0000819d.bin
5e47c5225d302061d079c84b1916cb4d4b4d982a71d9b083dd4503fe617b2974
pdf-font-stream PDF embedded font (sfnt) at offset 0x819D 5036 bytes
font_02_sfnt_off000092c6.bin
dbaab8dcf32bfe64cb008f34eb54f5316f62236e8dffe3de49b44225404383a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x92C6 2656 bytes
font_03_sfnt_off00009dca.bin
864cbe2c6973b44d2b71e19ffbffb2328dcb3759b07ceb43c11d5a372fc4956d
pdf-font-stream PDF embedded font (sfnt) at offset 0x9DCA 2328 bytes
font_04_sfnt_off0000a880.bin
d117309382da938f7dffedc42f90dd4217b4d540d75629b80669d975ecbc171e
pdf-font-stream PDF embedded font (sfnt) at offset 0xA880 2108 bytes
font_05_sfnt_off0000b24b.bin
538512be6c526ea957b587fa229624d829dca4873b622d187784a60d2c877fcd
pdf-font-stream PDF embedded font (sfnt) at offset 0xB24B 6640 bytes
font_06_sfnt_off0000c3e9.bin
22371b6bb7ed83de44911d5d3d76780e4c19a05cb107bff0db46962566921f35
pdf-font-stream PDF embedded font (sfnt) at offset 0xC3E9 12696 bytes
font_08_sfnt_off00010b2b.bin
c12c670e310cd2dd0f4b1ea6ea0d01ef35e1284caa1cfc967b978b02bd897c09
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B2B 3276 bytes