Malicious PDF — malware analysis report

Static analysis result for SHA-256 d5776f183f50f136…

MALICIOUS

PDF

40.1 KB Created: 2020-08-14 02:41:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c4aa7d11a2a1f09e79e3313a1577864d SHA-1: 1615033d8ddee4cba0ecffb61cec2adc65fe89aa SHA-256: d5776f183f50f136040d35eb827e75d294e7895dcb9f4777c73023cede2f97b7
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a prominent link to a known malicious redirector, ttraff.com, which is disguised as a "Chelan county sheriff report". The document also exhibits characteristics of a PDF link farm, with numerous links pointing to external resources, many of which are hosted on Shopify. The ML classifier strongly indicated maliciousness, supporting the conclusion that this PDF is designed to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=chelan+county+sheriff+report
    • http://files.tfamcon.com/uploads/1/3/0/7/130776795/eff2f1c7baeb6a2.pdf
    • http://jipunezo.christinestockediting.com/uploads/1/3/1/1/131164250/dutewib.pdf
    • http://files.guesthouseouassaggou.com/uploads/1/3/1/4/131438509/8192980.pdf
    • http://files.en.animalprograms.org/uploads/1/3/0/7/130739814/vedununuz.pdf
    • http://vemujore.shueyvilleia.com/uploads/1/3/1/8/131856145/vigujoripis.pdf
    • https://cdn.shopify.com/s/files/1/0448/1715/4208/files/bartok_mikrokosmos_volume_1.pdf
    • https://cdn.shopify.com/s/files/1/0428/0621/4819/files/ganonisibowos.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/99914628395.pdf
    • https://cdn.shopify.com/s/files/1/0438/3929/1554/files/os_axiomas_de_zurich.pdf
    • https://cdn.shopify.com/s/files/1/0433/6789/1094/files/pikufawa.pdf
    • https://cdn.shopify.com/s/files/1/0434/6527/7605/files/2964203866.pdf
    • https://cdn.shopify.com/s/files/1/0431/5758/6071/files/gepukivavosifijilutip.pdf
    • https://cdn.shopify.com/s/files/1/0429/1536/5031/files/konijopafoxemebobez.pdf
    • https://cdn.shopify.com/s/files/1/0430/5492/3925/files/wolinazideworo.pdf
    • https://cdn.shopify.com/s/files/1/0433/7644/3557/files/self_adjoint_operator.pdf
    • https://cdn.shopify.com/s/files/1/0438/2644/6498/files/examen_de_las_28_creencias_adventistas.pdf
    • https://cdn.shopify.com/s/files/1/0428/4638/8380/files/77702780822.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005f64.bin
49a9636e84bd3ecef478c6c14968f20ed3d3db6c84098e92d889735c51bec83c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F64 5112 bytes
font_01_sfnt_off000070c4.bin
6baf448fd9aaa074a5941816ee7528f2870c233693c2d7ae5f25e4c0b156eb1c
pdf-font-stream PDF embedded font (sfnt) at offset 0x70C4 10220 bytes