Malicious PDF — malware analysis report

Static analysis result for SHA-256 b13d27b3549da9f1…

MALICIOUS

PDF

36.5 KB Created: 2020-08-12 10:42:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e241e86f903cc622cf9c78f5c76bd1e9 SHA-1: c4d5fe94eee8b6d718e070e22e081069ccbe1ecc SHA-256: b13d27b3549da9f100cb4c0a2c04e2c53cad5d3153d7a7efd8d8f548244b5469
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a mass external link farm, with a primary malicious redirector URL embedded in the document body. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK indicates that the link https://ttraff.cc/pify?keyword=carol+of+the+bells+violin+duet+pdf leads to known malicious infrastructure. The ML classifier also strongly flagged this PDF as malicious. The document body text, though partially obfuscated, contains the same lure text as the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=carol+of+the+bells+violin+duet+pdf
    • http://files.cxdhomeandco.ca/uploads/1/3/1/0/131071137/f0dd5781.pdf
    • http://files.carmenjabaloyes.com/uploads/1/3/0/7/130776500/lagoruviveged_luwig.pdf
    • http://files.londontowalsingham.com/uploads/1/3/1/3/131384335/rosawure.pdf
    • http://files.cookiescutters.com/uploads/1/3/2/6/132682822/sawomiji_pelorilezisaje_gujapaxogabefos.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/39738284996.pdf
    • https://cdn.shopify.com/s/files/1/0431/7826/2689/files/99474017006.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/kaxoku.pdf
    • https://cdn.shopify.com/s/files/1/0435/5047/4403/files/kugeredozilepari.pdf
    • https://cdn.shopify.com/s/files/1/0436/0162/5252/files/sbi_bank_syllabus_2020_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/2732/5351/files/80122545769.pdf
    • https://cdn.shopify.com/s/files/1/0427/8370/3206/files/51291251985.pdf
    • https://cdn.shopify.com/s/files/1/0433/8250/5628/files/changing_to_word_doc.pdf
    • https://cdn.shopify.com/s/files/1/0429/1300/5724/files/calendario_sep_2020_mexico_pdf.pdf
    • https://cdn.shopify.com/s/files/1/0433/3253/4440/files/59577496309.pdf
    • https://cdn.shopify.com/s/files/1/0430/8982/1847/files/37585138101.pdf
    • https://cdn.shopify.com/s/files/1/0434/1284/8790/files/25422706132.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000051f6.bin
91da73495cbc44e28c3b0d0de6dde2c81de6b79c2231e47b3f7001218bc0613e
pdf-font-stream PDF embedded font (sfnt) at offset 0x51F6 5232 bytes
font_01_sfnt_off000063be.bin
378c6181f21222b7c5f67cb84893babc2748ca193d2f15874da02536f7db5b15
pdf-font-stream PDF embedded font (sfnt) at offset 0x63BE 9816 bytes