Malicious PDF — malware analysis report

Static analysis result for SHA-256 cbca0cd065871ce8…

MALICIOUS

PDF

42.5 KB Created: 2020-08-30 11:45:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cf6f2a76f605496eab62cac8640b07ae SHA-1: 370152a525678c9b3326e4783bc82133d3647fb8 SHA-256: cbca0cd065871ce8e80b4fb4b68a2079a6d59f4fdd5a1b4216411be3f55f88d4
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged as malicious by an ML classifier and contains a large number of embedded external links, characteristic of a link farm. One of these links, https://ttraff.com/wix?keyword=the+outliers+summary, points to known malicious redirector infrastructure. The document body itself appears to be largely obfuscated or corrupted, but the presence of the malicious URL and the link farm structure strongly suggest a malicious intent, likely to direct users to harmful content or phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=the+outliers+summary
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/16711599054.pdf
    • https://cdn.shopify.com/s/files/1/0440/7685/9557/files/english_sentences_with_tamil_meaning.pdf
    • https://cdn.shopify.com/s/files/1/0433/1631/4277/files/90766990463.pdf
    • https://cdn.shopify.com/s/files/1/0430/1327/5811/files/autoregressive_moving_average_model.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/5578033559.pdf
    • https://static.usrfiles.com/ugd/ca32a8_416cc12817fb4e1da00e4a6f6e3a9d41.pdf
    • https://static.usrfiles.com/ugd/5b5da7_9727fd5c46e54a1b954c5babac4661b1.pdf
    • https://static.usrfiles.com/ugd/ae059d_042f1d3e89c74111ab8263253829a787.pdf
    • https://static.usrfiles.com/ugd/599f1c_db3990f1ca88410bbabea6a1b8e25a26.pdf
    • https://cdn.shopify.com/s/files/1/0434/3640/8982/files/xibudabexotafuzup.pdf
    • https://cdn.shopify.com/s/files/1/0431/8216/2084/files/16975535972.pdf
    • https://cdn.shopify.com/s/files/1/0433/6127/1959/files/bakavu.pdf
    • https://cdn.shopify.com/s/files/1/0435/1878/7736/files/agricultural_economics_notes.pdf
    • https://cdn.shopify.com/s/files/1/0434/5567/6580/files/nuevo_acuerdo_de_paz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ab7.bin
e4e4355b336ddf35b949aa5c9f4d5f99b9eb716733a1b7389c6e16f24fc9d711
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AB7 4976 bytes
font_01_sfnt_off00007b80.bin
07ccd3d25fd954625723258a0e2ee5ec5a2049dba458e183cd8bba8f1d358d35
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B80 9964 bytes