Malicious PDF — malware analysis report

Static analysis result for SHA-256 7100f0c4695748b8…

MALICIOUS

PDF

40.5 KB Created: 2020-08-23 04:52:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c7d9a10458ccabd06709accfd908562f SHA-1: e73aaf226c0a643f2146fcd9cbbdcfe94d0d2a4d SHA-256: 7100f0c4695748b88638b47e69222ccb79d14badea93149ddbe814cbb1cc2767
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains a large number of embedded links, many of which point to external PDF files, indicating a link farm or SEO manipulation tactic. One prominent URL, 'https://ttraff.cc/pify?keyword=emerging+modes+of+business+answers', is flagged as a malicious redirector. The ML classifier also strongly indicated maliciousness. The document body appears to be obfuscated or corrupted, but the presence of the malicious redirector and the link farm strongly suggest an attempt to lead users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=emerging+modes+of+business+answers
    • http://wiwexotoj.fushionbeauty.studio/uploads/1/3/2/7/132740324/a23ab.pdf
    • http://sumiro.williamkdeugenio.com/uploads/1/3/2/6/132682051/zinediromisewipi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0428/7807/5036/files/20478396706.pdf
    • https://cdn.shopify.com/s/files/1/0430/9067/3813/files/sinajosiwot.pdf
    • https://cdn.shopify.com/s/files/1/0432/3275/5875/files/cholecystitis_history_taking.pdf
    • https://cdn.shopify.com/s/files/1/0440/1581/2766/files/22799393916.pdf
    • https://cdn.shopify.com/s/files/1/0431/8245/7000/files/13229685774.pdf
    • https://cdn.shopify.com/s/files/1/0439/1639/4648/files/nuxil.pdf
    • https://cdn.shopify.com/s/files/1/0431/2157/4049/files/vaduf.pdf
    • https://cdn.shopify.com/s/files/1/0433/6690/8054/files/menexogup.pdf
    • https://cdn.shopify.com/s/files/1/0427/6636/8935/files/bexedezeneg.pdf
    • https://cdn.shopify.com/s/files/1/0434/5495/5672/files/32102677584.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006142.bin
abe371fd9f4947ebf0e942a5e8f4cbe5be225fb482fd8d84b9904fffa5519ffe
pdf-font-stream PDF embedded font (sfnt) at offset 0x6142 5384 bytes
font_01_sfnt_off00007385.bin
f4da0a5977b07d60126f7504f1982e2e09adccf22c609b32df3d14dfa5100e5b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7385 9928 bytes