Malicious PDF — malware analysis report

Static analysis result for SHA-256 873a89df17149652…

MALICIOUS

PDF

38.5 KB Created: 2020-08-27 22:33:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0fe3754cea55cc34ffe032c1dfff76a3 SHA-1: be02a78d26fb261deb5ad26445a89fac72c0e9aa SHA-256: 873a89df171496527a8add8d4cca44d5b3f0e97ec1fab8f8f5fed1429b27e6dd
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

This PDF document is classified as malicious due to its extensive use of embedded links. The primary malicious URL, https://ttraff.me/pify?keyword=rhythm+cuckoo+clock+manual, is identified as a redirector. The document also contains a link farm pointing to numerous PDFs hosted on Shopify, likely to manipulate search engine results and obscure the malicious redirector. No scripts were extracted, but the structure and URL analysis strongly indicate a phishing or redirection attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/pify?keyword=rhythm+cuckoo+clock+manual
    • http://vepixudaz.healthymarathonmoms.com/uploads/1/3/2/7/132710714/8108924.pdf
    • https://cdn.shopify.com/s/files/1/0434/5489/0149/files/26476993213.pdf
    • https://cdn.shopify.com/s/files/1/0436/4979/4213/files/44549278989.pdf
    • https://cdn.shopify.com/s/files/1/0431/0702/5056/files/solomons_organic_chemistry_solutions_manual.pdf
    • https://cdn.shopify.com/s/files/1/0435/1026/8064/files/52550788699.pdf
    • https://cdn.shopify.com/s/files/1/0437/3826/7809/files/75085586157.pdf
    • https://cdn.shopify.com/s/files/1/0428/5667/7543/files/activar_office_plus_activar_office_plus.pdf
    • https://cdn.shopify.com/s/files/1/0430/2045/1997/files/62507247238.pdf
    • https://cdn.shopify.com/s/files/1/0435/6590/8123/files/89737099178.pdf
    • https://cdn.shopify.com/s/files/1/0429/0006/2371/files/fusion_android_13_teq.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b0e.bin
6956688ac05c4fe0fd4c263d3e023eb913effcdff3aef802f3a26349a151d714
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B0E 4936 bytes
font_01_sfnt_off00006bc4.bin
992961276d05675ea8b2b5eba25382dbc539748d8f1dba49f2761477c3db2848
pdf-font-stream PDF embedded font (sfnt) at offset 0x6BC4 10012 bytes