Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dff18d0685bfd1f…

MALICIOUS

PDF

56.0 KB Created: 2020-08-08 13:03:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e6a8930e9eb9d142432f3f154a72145e SHA-1: 87bd04b579b4349814a34e33fd95ee09c12248c7 SHA-256: 9dff18d0685bfd1f7cfb80e82dfddc7af5b2fd4b49918bdf8c2d9cdd9952f348
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, a common tactic for SEO poisoning or link farms. One of these URLs, https://ttraff.com/pify?keyword=biogenic+sa+200+pdf, is identified as a malicious redirector. The ML classifier also strongly indicated maliciousness. No scripts were extracted, but the presence of the malicious redirector suggests the document is designed to lure users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=biogenic+sa+200+pdf
    • http://files.poultryserviceassociation.com/uploads/1/3/2/7/132740633/gudebafezoja_lanalosib.pdf
    • http://files.classicalmusictoday.net/uploads/1/3/2/3/132303382/xobaxezudawatovotaze.pdf
    • http://files.rim-foundation.org/uploads/1/3/1/4/131453214/wolinugime_jenotenawapi_wituvixiwulejam.pdf
    • http://files.hanoverbrass.com/uploads/1/3/0/7/130775712/8283255.pdf
    • https://cdn.shopify.com/s/files/1/0430/1311/1961/files/32371984948.pdf
    • https://cdn.shopify.com/s/files/1/0432/0041/3856/files/gisimafodonegitaxane.pdf
    • https://cdn.shopify.com/s/files/1/0437/0219/0235/files/admiral_byrd_diary_free.pdf
    • https://cdn.shopify.com/s/files/1/0433/9105/8083/files/30291600260.pdf
    • https://cdn.shopify.com/s/files/1/0431/6885/8280/files/31824775420.pdf
    • https://cdn.shopify.com/s/files/1/0430/7514/1794/files/51027108163.pdf
    • https://cdn.shopify.com/s/files/1/0434/4227/4454/files/nojezegepewowopemopo.pdf
    • https://cdn.shopify.com/s/files/1/0431/4877/1488/files/chalk_brush_photoshop.pdf
    • https://cdn.shopify.com/s/files/1/0432/5300/6494/files/merriam_webster_s_advanced_learner_s_english_dictionary.pdf
    • https://cdn.shopify.com/s/files/1/0434/8326/7234/files/kefewudekenufan.pdf
    • https://cdn.shopify.com/s/files/1/0431/2327/7973/files/14165491284.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006421.bin
c999d68dc1bc435787e0dfff239b4309216e3b4722525104dfdf729fca42d10c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6421 4056 bytes
font_01_sfnt_off00007233.bin
7799b6806a3fecfc6a9fa09db992b66af1d047235168d2a3173b2a27cf4ec6b8
pdf-font-stream PDF embedded font (sfnt) at offset 0x7233 5228 bytes
font_02_sfnt_off000083f5.bin
b455134215c1f127543c9e9325f175308c359cbf98b278a12a4b01fea3a88c9a
pdf-font-stream PDF embedded font (sfnt) at offset 0x83F5 6092 bytes
font_03_sfnt_off000093c8.bin
8714b153f0853aba7fc630f695ff937ba04e878ee48907eec23efef4905748fe
pdf-font-stream PDF embedded font (sfnt) at offset 0x93C8 14720 bytes
font_04_sfnt_off0000c1eb.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0xC1EB 4324 bytes