Malicious PDF — malware analysis report

Static analysis result for SHA-256 794e2e3cf9ca473a…

MALICIOUS

PDF

46.5 KB Created: 2020-08-03 19:16:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 72333a330804fabd050c2547fe7ced2c SHA-1: 6fad445d335e6e573ad5aa1b62244641d366220c SHA-256: 794e2e3cf9ca473aa7d451109dc5a1245bb8ddc4362d883c3073d985a7154932
194 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous links, including one to a known malicious redirector at ttraff.com, which is designed to lead users to further malicious content. The document body, though heavily obfuscated, contains text related to 'cash book problems and solutions pdf' and references wkhtmltopdf, suggesting a lure to download or view a document. The presence of multiple external PDF links, many pointing to Shopify, indicates a link farm strategy to improve SEO for malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=three+column+cash+book+problems+and+solutions+pdf
    • http://files.questadolcevita.com/uploads/1/3/0/8/130873932/12fc7c.pdf
    • http://files.america1funding.com/uploads/1/3/1/3/131398547/juboxom-mijesesudova-lubiguregi-zifege.pdf
    • http://files.littlebitofheavenadoptionreferral.com/uploads/1/3/0/7/130775813/741b3.pdf
    • http://files.qstreetband.com/uploads/1/3/0/9/130969080/jakusafi.pdf
    • http://files.holosterra.com/uploads/1/3/1/6/131606059/dopabavi_jerupefo_wunufupezotagu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/mupuxisupevijerabufogete.pdf
    • https://cdn.shopify.com/s/files/1/0429/6284/5859/files/futifivaronivajifu.pdf
    • https://cdn.shopify.com/s/files/1/0431/7813/1611/files/xonokafilolol.pdf
    • https://cdn.shopify.com/s/files/1/0435/4395/3563/files/my_crown_fell_off_can_i_eat.pdf
    • https://cdn.shopify.com/s/files/1/0431/5129/4619/files/xolajugenezawawetesef.pdf
    • https://cdn.shopify.com/s/files/1/0438/4695/9261/files/mumofefoxaxedi.pdf
    • https://cdn.shopify.com/s/files/1/0432/3128/1312/files/lotuzurewodeme.pdf
    • https://cdn.shopify.com/s/files/1/0431/2052/5476/files/ramaf.pdf
    • https://cdn.shopify.com/s/files/1/0434/6180/4198/files/6442820030.pdf
    • https://cdn.shopify.com/s/files/1/0436/4907/3312/files/zisesadumakef.pdf
    • https://cdn.shopify.com/s/files/1/0433/6972/6110/files/tufarumusigogenop.pdf
    • https://cdn.shopify.com/s/files/1/0431/0401/0389/files/2577340270.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/53059057271.pdf
    • https://cdn.shopify.com/s/files/1/0439/2674/9339/files/skyrim_hrothmund_s_barrow.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007684.bin
f7625689a18a6dd12edac9f36287e0dec57909b80b76b762392588d1a1b62b74
pdf-font-stream PDF embedded font (sfnt) at offset 0x7684 5548 bytes
font_01_sfnt_off0000892f.bin
8bde729e5e22d928b1995e45a6effcf0a3204a804569cdd1ce5c2401e0cc2a3f
pdf-font-stream PDF embedded font (sfnt) at offset 0x892F 10256 bytes