Malicious PDF — malware analysis report

Static analysis result for SHA-256 d305628de7146847…

MALICIOUS

PDF

44.7 KB Created: 2020-08-13 03:55:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2189ba3d9ee836cebf3a8a7909882263 SHA-1: bb2ee37ef1d7322b7d980b30d89a100508e608c5 SHA-256: d305628de71468479e0d96a0c6689360efa54c55d13c0d06b7fe46393bfa17b3
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a mass of external links, including one pointing to a known malicious redirector at 'ttraff.cc'. The document body, though heavily obfuscated, contains text suggesting a lure related to 'Alto professional ts215 pdf' and includes the malicious URL. This indicates the document is designed to redirect users to malicious content, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=alto+professional+ts215+pdf
    • http://files.sunnysidehomedecor.com/uploads/1/3/1/4/131453198/tubuzowemozonegogol.pdf
    • http://bakuter.changemakerllp.co.uk/uploads/1/3/0/7/130776031/f56699025.pdf
    • http://files.frauhoeckner.com/uploads/1/3/1/3/131380213/tupivupatop.pdf
    • http://kaviji.noondayfarm.org/uploads/1/3/2/7/132712615/nuvobadutafik_xisesimukipifu_lepud.pdf
    • https://cdn.shopify.com/s/files/1/0429/5933/9679/files/sojufob.pdf
    • https://cdn.shopify.com/s/files/1/0433/2224/5273/files/21722245754.pdf
    • https://cdn.shopify.com/s/files/1/0428/8570/9987/files/country_code_64.pdf
    • https://cdn.shopify.com/s/files/1/0437/8460/1752/files/les_accents_cm1.pdf
    • https://cdn.shopify.com/s/files/1/0434/2887/2359/files/51962787120.pdf
    • https://cdn.shopify.com/s/files/1/0441/2620/8152/files/xujatoloroxo.pdf
    • https://cdn.shopify.com/s/files/1/0429/5966/7363/files/appsc_panchayat_secretary_previous_papers_2020.pdf
    • https://cdn.shopify.com/s/files/1/0433/7473/9607/files/23046393616.pdf
    • https://cdn.shopify.com/s/files/1/0436/9979/8166/files/elastic_collision_in_two_dimension_derivation.pdf
    • https://cdn.shopify.com/s/files/1/0434/5646/3014/files/63955472399.pdf
    • https://cdn.shopify.com/s/files/1/0440/6909/3541/files/ruluzofuzobitizafanezu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006569.bin
3fbbf8d6e8d23002454ff2ca4c8745c4e45a50488e389b2627b07f264f4f2c92
pdf-font-stream PDF embedded font (sfnt) at offset 0x6569 5332 bytes
font_01_sfnt_off00007799.bin
60cdc08e2f3e7d1e6c61e2e52f398a16b001957c697abb6b08f0a91144dd7b34
pdf-font-stream PDF embedded font (sfnt) at offset 0x7799 15016 bytes