Malicious PDF — malware analysis report

Static analysis result for SHA-256 e07693848910f4d1…

MALICIOUS

PDF

70.0 KB Created: 2020-08-29 07:47:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dde4a653f8cb08f33d8857dd5ff67f78 SHA-1: db0a8a0ff63d12d68431f4c52369745292a5b9c4 SHA-256: e07693848910f4d1daa59af95354ad167be4f4bc9a50f52a544a0563bb52bd0e
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/wix?keyword=berenstain+bears+and+the+mean+drunk'. Additionally, it exhibits a PDF link farm heuristic, indicating a large number of external links, many of which point to static.usrfiles.com. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same URL as the malicious redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=berenstain+bears+and+the+mean+drunk
    • https://cdn.shopify.com/s/files/1/0440/7951/3752/files/58391499108.pdf
    • https://cdn.shopify.com/s/files/1/0430/1737/1797/files/56093044779.pdf
    • https://cdn.shopify.com/s/files/1/0436/1984/4258/files/abbotsford_weather_report_today.pdf
    • https://static.usrfiles.com/ugd/b8c837_22d89e09ffd047df98b25af2dc1b2302.pdf
    • https://static.usrfiles.com/ugd/b8c837_31301d09ce16491a85013ce73f17303e.pdf
    • https://static.usrfiles.com/ugd/b8c837_0b6c745be44b4880b4906a0e94e2621d.pdf
    • https://static.usrfiles.com/ugd/b8c837_d03c5b973cf44b979260c8ccfe8d9224.pdf
    • https://static.usrfiles.com/ugd/b8c837_b7f236eb8bf84af8bce360f1a50728c1.pdf
    • https://static.usrfiles.com/ugd/b8c837_4d88feceb1d34f07a902010f38dc25c3.pdf
    • https://static.usrfiles.com/ugd/b8c837_ac53266fbdf14e64bee3a99baf17e93b.pdf
    • https://static.usrfiles.com/ugd/b8c837_2984490deefa4548872edf3be348ae19.pdf
    • https://cdn.shopify.com/s/files/1/0437/2050/7546/files/8265134571.pdf
    • https://cdn.shopify.com/s/files/1/0437/2732/3301/files/23729175080.pdf
    • https://cdn.shopify.com/s/files/1/0433/6903/7980/files/nc_math_3_final_exam_review.pdf
    • https://cdn.shopify.com/s/files/1/0431/2160/6818/files/rotejejoxaki.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d49c.bin
fca11257a0b3f1d31cf9e2d598b6ee305d9f59d1d6652e317bfb17dc6359f05e
pdf-font-stream PDF embedded font (sfnt) at offset 0xD49C 5288 bytes
font_01_sfnt_off0000e662.bin
e632c58c584ed7f6183a7d573ee280b41915aeb0f30f2cc59d93ddc2a068ae81
pdf-font-stream PDF embedded font (sfnt) at offset 0xE662 10680 bytes