Malicious PDF — malware analysis report

Static analysis result for SHA-256 701bb1afe29493dc…

MALICIOUS

PDF

48.8 KB Created: 2020-08-21 00:30:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 36b53fc2b2f8c8fa07f27c317aebb92d SHA-1: 0e52b23465df2d214918441d0654eabca8001b6f SHA-256: 701bb1afe29493dc3eed3146319c6af11b1095623d7a7b00699141a4970d4127
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file contains numerous links, including one pointing to known malicious redirector infrastructure at ttraff.com. The document body, though partially obfuscated, contains the URL and text suggesting a lure related to a video game guide. The presence of a link farm and a critical ML classification further support its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=rotten+vale+guide+monster+hunter+world
    • http://files.gregbenken.com/uploads/1/3/0/7/130738892/1994898.pdf
    • http://lavime.purelivingwithlisamorton.com/uploads/1/3/1/3/131398547/9085542.pdf
    • http://tanufek.bestdiabeticmealplans.com/uploads/1/3/1/3/131383483/nikunolanozeto-lapuxanupumon.pdf
    • http://files.bdfotografika.com/uploads/1/3/0/7/130738859/jazebagosiw-degoxesanak-kejazewedox-jodipu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0427/6515/6508/files/65967193768.pdf
    • https://cdn.shopify.com/s/files/1/0428/7689/5398/files/gimawot.pdf
    • https://cdn.shopify.com/s/files/1/0429/8512/8090/files/3319323152.pdf
    • https://cdn.shopify.com/s/files/1/0436/8682/2053/files/zilamanegopix.pdf
    • https://cdn.shopify.com/s/files/1/0434/9201/6280/files/amapiano_2019_jobe.pdf
    • https://cdn.shopify.com/s/files/1/0433/9718/5701/files/43550475607.pdf
    • https://cdn.shopify.com/s/files/1/0433/6618/7176/files/39074533886.pdf
    • https://cdn.shopify.com/s/files/1/0431/1210/4103/files/relatorio_de_auditoria_financeira.pdf
    • https://cdn.shopify.com/s/files/1/0432/8233/3856/files/serenade_schubert_liszt.pdf
    • https://cdn.shopify.com/s/files/1/0433/7218/3710/files/altium_designer_17_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/3006/0955/files/totelometagani.pdf
    • https://cdn.shopify.com/s/files/1/0437/1175/8491/files/gejanogiwateroto.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000711d.bin
797ce16e037fd9bee8296ca473f0277aa37d747fe95fbb3d5c77c5370b6815ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x711D 4468 bytes
font_01_sfnt_off000080c9.bin
6f6e7f166e26eb62d5d18e1f6627d413ede64ff25c9b56e2edc5a302b4705cc3
pdf-font-stream PDF embedded font (sfnt) at offset 0x80C9 5400 bytes
font_02_sfnt_off0000930f.bin
355d8de128d09d9bc4406634bc861b699cdf52a03ef98a1a1dc36c6f21015492
pdf-font-stream PDF embedded font (sfnt) at offset 0x930F 9980 bytes