Malicious PDF — malware analysis report

Static analysis result for SHA-256 705da7990e46140a…

MALICIOUS

PDF

122.7 KB Created: 2020-08-10 21:29:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 03fef950eb7b6860152bef65e4f26576 SHA-1: 158a336ec81b3472757f7f72d5e16eb4f847da87 SHA-256: 705da7990e46140a0677be3c1aca0f724fe33e4caa5025a974e3d366d7355f05
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous links, including one to a known malicious redirector at ttraff.com. The document body, though heavily obfuscated, contains the same URL, suggesting it's the primary lure. The heuristic firings confirm the presence of malicious redirector links and a link farm, indicating a phishing or scam attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=alter+ego+a2+plus+methode+de+francais+pdf
    • http://files.goldstripecoffee.com/uploads/1/3/0/7/130738943/bofezebav.pdf
    • http://files.stefanpetrunov.com/uploads/1/3/2/7/132740278/foram_zuzirakag_pifivufa_fewasanoxabej.pdf
    • http://files.spirithalfmarathon.com/uploads/1/3/2/8/132814371/3376789.pdf
    • http://files.yaahi.org/uploads/1/3/0/7/130738960/musekelivubobas.pdf
    • http://files.unwhomecoming.com/uploads/1/3/0/7/130776046/kobuzorojapeg_dukadujewevuz.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0435/9634/9602/files/jovud.pdf
    • https://cdn.shopify.com/s/files/1/0437/7932/6110/files/vifavatisuxuso.pdf
    • https://cdn.shopify.com/s/files/1/0438/6160/6550/files/xadiworikedizat.pdf
    • https://cdn.shopify.com/s/files/1/0437/1863/9765/files/56298053091.pdf
    • https://cdn.shopify.com/s/files/1/0437/9561/1809/files/dragon_s_dogma_cursed_carving.pdf
    • https://cdn.shopify.com/s/files/1/0429/6704/0154/files/43816497603.pdf
    • https://cdn.shopify.com/s/files/1/0429/2041/1303/files/81642261494.pdf
    • https://cdn.shopify.com/s/files/1/0445/3256/4132/files/digestive_system_test_ks3.pdf
    • https://cdn.shopify.com/s/files/1/0438/0947/2669/files/74284032366.pdf
    • https://cdn.shopify.com/s/files/1/0430/4646/9793/files/loxugidan.pdf
    • https://cdn.shopify.com/s/files/1/0429/5337/5897/files/29032713102.pdf
    • https://cdn.shopify.com/s/files/1/0431/8950/2110/files/pesijumudezewewunoviw.pdf
    • https://cdn.shopify.com/s/files/1/0430/1553/6793/files/giwuxep.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018c00.bin
a9d6247e0ad5578f2ae7f48829610b18a2943d13f67a3ea000e91830245841eb
pdf-font-stream PDF embedded font (sfnt) at offset 0x18C00 5692 bytes
font_01_sfnt_off00019f37.bin
872bff968071f86ddfb9190152f2606cf913291dc40770c3e80a42f997cbb67c
pdf-font-stream PDF embedded font (sfnt) at offset 0x19F37 12848 bytes
font_02_sfnt_off0001c791.bin
f9eba8a24f5ced40287a06ea1ea1b3306d4cfbe5d0e0171be7ad806b5c144e70
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C791 16080 bytes