Malicious PDF — malware analysis report

Static analysis result for SHA-256 a6a39dbc26a45243…

MALICIOUS

PDF

90.5 KB Created: 2020-09-18 13:30:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2a99c4145395ed522a961a1c9d879a53 SHA-1: 6a7c2d50930f81c0e2a9d1ecb0e0cc7a52c0782a SHA-256: a6a39dbc26a452438ece2e53fd50cd47fec3b4b2bf90807f6784b73a95f88a06
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains multiple embedded links, with one identified as a malicious redirector. The document body, though heavily obfuscated, contains the string 'Ley de inercia' and the malicious URL 'https://ttraff.link/pify?keyword=ley+de+inercia', suggesting a lure to external content. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' confirms the presence of malicious redirector infrastructure. The ML classifier also strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/pify?keyword=ley+de+inercia
    • http://kedava.artsoffmain.ca/uploads/1/3/0/8/130814161/sijotokenetimi.pdf
    • http://zuxirev.daniellereneewallace.com/uploads/1/3/1/0/131070171/goxijufigepupof-tekun-badovezirijofub-selinudatufe.pdf
    • http://files.sstherapyinjuryclinic.co.uk/uploads/1/3/0/8/130874115/pakodejape.pdf
    • https://cb10fa2e-44d5-4bef-971d-f8cb8f8c4656.filesusr.com/ugd/60e703_9f453d161862420390b715b585d96cd8.pdf?index=true
    • https://82757b28-7c4a-47a0-ad27-c96179c1e23c.filesusr.com/ugd/b50c55_eaae167c51e94f418ca7fcf984e7751e.pdf?index=true
    • https://5bb3c3e7-3725-4c39-a86d-0c1e979f4cc1.filesusr.com/ugd/2b25b5_089d1a6444e54ec4bf62610c7e8b6c63.pdf?index=true
    • https://35b96413-f734-4c04-b1b8-9c4de42de6e1.filesusr.com/ugd/20d83a_44323e9145804673ae1b7b59577e1921.pdf?index=true
    • https://390c5590-b8ef-4a0c-a55e-6f7e44156398.filesusr.com/ugd/b98abb_c13a5d0998584e0c9a1e3c95188e2fad.pdf?index=true
    • https://b756ccaf-2f2d-44d9-a0ac-b63ed3ad1a17.filesusr.com/ugd/4cf28d_b0771c178e124894979a7d2706096f90.pdf?index=true
    • https://967babce-aeaf-4ad3-a321-6cd378e0df1d.filesusr.com/ugd/45fd81_568f81327924446eaf579bcb754849dd.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0462/1293/9929/files/formato_de_cdula_venezolana_totalmente_editable.pdf
    • https://cdn.shopify.com/s/files/1/0435/8530/6782/files/writing_answer_sheet_ielts.pdf
    • https://cdn.shopify.com/s/files/1/0431/3382/9277/files/rijutasenafonadolukotere.pdf
    • https://cdn.shopify.com/s/files/1/0430/8067/9577/files/chevrolet_captiva_manual_bekas_bandung.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010427.bin
afc51fc9c28f21e617efaeec64bb89782c086b5d01863d40f1cd9902617d5df0
pdf-font-stream PDF embedded font (sfnt) at offset 0x10427 4764 bytes
font_01_sfnt_off00011476.bin
b7a6b9277c8bb4978b603cfa82f685e60d00cce881d10e07b55b17e2c2b314ba
pdf-font-stream PDF embedded font (sfnt) at offset 0x11476 15988 bytes
font_02_sfnt_off000145a6.bin
a777924a0d8f80f738c66f35a894218ad4713bfafb4e50fe2921472a37d0ba07
pdf-font-stream PDF embedded font (sfnt) at offset 0x145A6 16384 bytes