Malicious PDF — malware analysis report

Static analysis result for SHA-256 dde3b1085e01a8da…

MALICIOUS

PDF

40.3 KB Created: 2020-08-14 14:38:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d3ab4fa7b429693b97f776866b693518 SHA-1: ced78631f8ea5d26720b958917fb3fb173012bd0 SHA-256: dde3b1085e01a8da2ec8d17f35422bb8e9b592df782e6b659d42837727e57a6e
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wb?keyword=orphan%20drug%20list%20pdf'. This URL is presented within the document body, suggesting a lure to trick users into clicking it. The presence of numerous other PDF links, many hosted on Shopify, indicates a potential link farm or SEO poisoning attempt to distribute malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=orphan%20drug%20list%20pdf
    • http://tiguzinox.mary-johnson.com/uploads/1/3/1/3/131379591/4859785.pdf
    • http://nutalifet.thesleepingstoryteller.com/uploads/1/3/1/4/131438268/705165.pdf
    • http://kotuvenu.lecontent.eu/uploads/1/3/1/6/131607240/wirekagoxatatotutumi.pdf
    • http://files.liguangyi.com/uploads/1/3/1/4/131437862/wowebogik_vosidabilixizek.pdf
    • https://cdn.shopify.com/s/files/1/0439/4654/1211/files/73766255230.pdf
    • https://cdn.shopify.com/s/files/1/0431/5463/6966/files/gilavofuxinoteruzaxutuwu.pdf
    • https://cdn.shopify.com/s/files/1/0429/8548/8543/files/36195558419.pdf
    • https://cdn.shopify.com/s/files/1/0431/4211/9592/files/42116446916.pdf
    • https://cdn.shopify.com/s/files/1/0427/9789/1751/files/2780760712.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/85947343199.pdf
    • https://cdn.shopify.com/s/files/1/0434/1248/8348/files/74638357184.pdf
    • https://cdn.shopify.com/s/files/1/0437/5350/4917/files/don_t_starve_krampus.pdf
    • https://cdn.shopify.com/s/files/1/0430/8090/8954/files/kilemenurog.pdf
    • https://cdn.shopify.com/s/files/1/0435/4536/2591/files/58033052650.pdf
    • https://cdn.shopify.com/s/files/1/0431/4929/5776/files/bilangan_berpangkat_dan_bentuk_akar.pdf
    • https://cdn.shopify.com/s/files/1/0453/5566/3515/files/weight_lifting_for_female_beginners.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000060a9.bin
299d23ef20e49ceb286e9d71faa22321d94fd36e8b6d661cdb80c0aad895d6c8
pdf-font-stream PDF embedded font (sfnt) at offset 0x60A9 5328 bytes
font_01_sfnt_off000072b6.bin
4f0003de886d3266e8542e2855ae15eb6eb7faf46e18b5180ed2aad9ecb98b29
pdf-font-stream PDF embedded font (sfnt) at offset 0x72B6 9980 bytes