Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b6e1afc3b0da19d…

MALICIOUS

PDF

50.5 KB Created: 2020-09-01 14:10:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1d49fe6a1c8c5151c38ea10f29560087 SHA-1: 66a2e410ed5837654a839de22dd216657b460ee7 SHA-256: 8b6e1afc3b0da19d3bd11b5c9a236226374927796e18ad476b8eacc7c818ab8c
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.me/wix?keyword=mumbai+local+tour+guide'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, including one to 'https://static.usrfiles.com/ugd/b8c837_6c308b80a8334f6cbbac0840859dd934.pdf'. The ML classifier also strongly flagged this PDF as malicious. The document body appears to be obfuscated or corrupted, but the presence of the malicious URL is the primary indicator of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=mumbai+local+tour+guide
    • https://static.usrfiles.com/ugd/b8c837_6c308b80a8334f6cbbac0840859dd934.pdf
    • https://static.usrfiles.com/ugd/3b7182_f1ac2734feae4b35b1dd7a990904da12.pdf
    • https://static.usrfiles.com/ugd/b8c837_fd95d354f52045b6937cb42309b17429.pdf
    • https://static.usrfiles.com/ugd/b8c837_b0488c9653454262809efc29948d737d.pdf
    • https://static.usrfiles.com/ugd/d902bb_2f8cf4fa73e447338a0bbee0bc81bdff.pdf
    • https://static.usrfiles.com/ugd/6924eb_f6caad470f32446d968ef7e0576b1bc3.pdf
    • https://static.usrfiles.com/ugd/b8c837_a1ccccb3e0484a8fbc947a367d1542cd.pdf
    • https://cdn.shopify.com/s/files/1/0437/1959/0040/files/vumubu.pdf
    • https://cdn.shopify.com/s/files/1/0435/1796/8543/files/bikig.pdf
    • https://cdn.shopify.com/s/files/1/0430/7347/0618/files/12992813399.pdf
    • https://cdn.shopify.com/s/files/1/0430/9201/7305/files/kaplan_step_2_cs_core_cases.pdf
    • https://cdn.shopify.com/s/files/1/0453/9963/8184/files/corel_to_jpg_converter_free.pdf
    • https://cdn.shopify.com/s/files/1/0435/4719/7594/files/adventure_time_wallpaper_android.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000089ee.bin
eee9c8dc8becb9a0a6d68c21289d681534f789d343976999b22a008f84b80625
pdf-font-stream PDF embedded font (sfnt) at offset 0x89EE 5228 bytes
font_01_sfnt_off00009b9c.bin
742e443d064c16c56899851512f3ce806f42db647590b2d3fb98f2b34b1f8c89
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B9C 9956 bytes