Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ef0983180a22c5b…

MALICIOUS

PDF

45.8 KB Created: 2020-09-02 03:45:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 28e5cd6feb4cf906fb62307e57d71efd SHA-1: 0baceab4279bc7d68f642c426d693d3e0dc8992f SHA-256: 7ef0983180a22c5b924c32ab18c52c249b43a304ab358b50b016d0025e294520
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link farm with 28 external PDF links, many of which point to potentially malicious redirector infrastructure. The primary malicious URL identified is https://ttraff.ru/wix?keyword=easter+cryptogram+answers, which is flagged as a malicious redirector. The document body, though heavily obfuscated, contains references to this URL and other PDF links, suggesting an attempt to drive traffic to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=easter+cryptogram+answers
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/b8c837_5444f467fc5a44e5adaaa0d161119b7f.pdf
    • https://static.usrfiles.com/ugd/9c43ec_a016ef12ed6241ca96d6fa31069f70dd.pdf
    • https://static.usrfiles.com/ugd/724bd4_31e09e56d0bd400bb660583bfc3438b5.pdf
    • https://static.usrfiles.com/ugd/b8c837_a0a961f29403455680cf338ce212e6d5.pdf
    • https://static.usrfiles.com/ugd/b8c837_fb6985de4f654a1cb937a6641e90bf53.pdf
    • https://static.usrfiles.com/ugd/b42fd6_b5286213f1a542edba2e42709e9771df.pdf
    • https://static.usrfiles.com/ugd/accd1f_84f3534910014be891cb1e0aa34ad956.pdf
    • https://static.usrfiles.com/ugd/b8c837_8643c4b1f748493db9efe68227e26d45.pdf
    • https://static.usrfiles.com/ugd/4f92c1_492a901d1d0443349f7e3477ba43252f.pdf
    • https://cdn.shopify.com/s/files/1/0435/6734/9923/files/learn_assyrian_language.pdf
    • https://cdn.shopify.com/s/files/1/0431/3025/7568/files/microsoft_active_directory_free.pdf
    • https://cdn.shopify.com/s/files/1/0435/5670/0319/files/bd_chaurasia_general_anatomy_5th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0431/4277/4938/files/67806984106.pdf
    • https://cdn.shopify.com/s/files/1/0434/5787/2033/files/bhagavad_gita_quotes_in_marathi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006935.bin
ec48d6ce3358a352a4693a4dfe5aa2f4c6c5c4e6405a9963108ce8e4e22ee17c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6935 5372 bytes
font_01_sfnt_off00007b85.bin
5132e990ff94654e81ab2e1f2e9d5889b2524d5e94b26671e4c1f024dd450fea
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B85 14664 bytes