Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ce46f00f187a804…

MALICIOUS

PDF

44.7 KB Created: 2020-08-17 17:16:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c32e8f75ad4e93c58020a74a716cdeb1 SHA-1: a98e6ec6249c7f80974d91cbb7e532d4215df22b SHA-256: 7ce46f00f187a804c51304f3735fb551c3420c8e6091b9452ddf8fc7c07f55d0
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded links, many of which point to potentially malicious redirectors or link farms. One prominent URL, 'https://ttraff.ru/pify?keyword=adobe+media+encoder+2017+free', is flagged as a known malicious redirector. The document body, though heavily obfuscated, also contains this URL, suggesting an attempt to trick users into downloading or accessing malicious content under the guise of software. No scripts were extracted, but the PDF structure and embedded links strongly indicate a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=adobe+media+encoder+2017+free
    • http://lopopu.spanishgrantbayside.com/uploads/1/3/1/6/131637027/a0bb63d82d4.pdf
    • http://files.angeladaley.com/uploads/1/3/1/6/131607467/sefadiguketa.pdf
    • http://files.dorothyfromkansas.com/uploads/1/3/0/7/130775382/duremi.pdf
    • http://files.wingspan-wellness.com/uploads/1/3/1/4/131406717/6bc09.pdf
    • http://files.burghyart.com/uploads/1/3/1/8/131871772/vevelu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0427/4195/6775/files/kuzij.pdf
    • https://cdn.shopify.com/s/files/1/0438/8805/0328/files/dream_girl_full_movie_123mkv.pdf
    • https://cdn.shopify.com/s/files/1/0433/0579/5752/files/25668487750.pdf
    • https://cdn.shopify.com/s/files/1/0427/7954/1671/files/weletuwazosiworipase.pdf
    • https://cdn.shopify.com/s/files/1/0439/1282/2939/files/enter_the_gungeon_prime_primer.pdf
    • https://cdn.shopify.com/s/files/1/0432/4950/0315/files/zewusajimifo.pdf
    • https://cdn.shopify.com/s/files/1/0432/3826/0898/files/ggplot_axis_labels_rotate.pdf
    • https://cdn.shopify.com/s/files/1/0434/5459/5224/files/aarti_balkrishna_ki_kije.pdf
    • https://cdn.shopify.com/s/files/1/0432/8210/4478/files/histoire_de_l_orthographe_franaise.pdf
    • https://cdn.shopify.com/s/files/1/0440/4002/8325/files/shri_amarnath_yatra_video.pdf
    • https://cdn.shopify.com/s/files/1/0428/5969/2198/files/mufijukalomerowo.pdf
    • https://cdn.shopify.com/s/files/1/0433/6130/4727/files/rukolopatamivonujezum.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006603.bin
1669ce7631253481302f6b3496b676021af7a72d4362cf813d212283d9b1da57
pdf-font-stream PDF embedded font (sfnt) at offset 0x6603 5492 bytes
font_01_sfnt_off0000789f.bin
f97d33c5e055cd34d9072d8681101bd34ddaed1c98f5a49cc36a17f7959c4cc8
pdf-font-stream PDF embedded font (sfnt) at offset 0x789F 14476 bytes