Malicious PDF — malware analysis report

Static analysis result for SHA-256 e15c6a4d07150957…

MALICIOUS

PDF

45.3 KB Created: 2020-11-01 10:56:06 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-14
MD5: 7d9003e56be12d3eaf44002fc73a80d9 SHA-1: e5fccf56b55dd05fd52d6bcff40420ff403bf9e1 SHA-256: e15c6a4d07150957d88fc6c23e07e7392b3826087cbcdf0baeca2aa33c2fe520
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous links, including one pointing to known malicious redirector infrastructure at 'ttraff.cc'. The document body, though heavily obfuscated, contains references to 'temporal concepts worksheets free' and includes the malicious URL, suggesting a lure for users seeking educational content. The presence of many external PDF links, some benign and some potentially malicious, indicates a link farm or redirection strategy.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/123?keyword=temporal+concepts+worksheets+free In PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/mijedusovineti/15006208996.pdfIn PDF document text
    • https://s3.amazonaws.com/paxivogedewilu/wipeout_hacked_apk_download.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0484/3244/7642/files/enol_and_enolate_practice_problems.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8bf4a747-aa42-4929-a50e-6d241b04cee6/exercice_prsent_de_l_indicatif_cm2.pdfIn PDF document text
    • https://s3.amazonaws.com/sedimeraxufi/relipexi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b4997ff1-0f9b-4e3e-ae17-ce1667b95af0/79737513775.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0465/0241/2446/files/dituz.pdfIn PDF document text
    • https://s3.amazonaws.com/zirojopemup/b_tech_civil_engineering_syllabus_2018.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/9699/0115/files/resumen_segunda_guerra_mundial_4_eso.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0502/9865/0789/files/532335459.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e3a40e34-922f-4db2-a0a7-2108abb5e223/pikiresa.pdfIn PDF document text
    • https://s3.amazonaws.com/xajowu/nikon_lens_repair_seattle.pdfIn PDF document text
    • https://s3.amazonaws.com/rekorewexidiwo/posabarorirekugo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b9594ef6-83dd-40cb-bfbe-3aba24023b38/ridakunevolev.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c1e8fa78-85ee-4351-90ba-6b77515daaec/35961948114.pdfIn PDF document text
    • https://s3.amazonaws.com/remoxi/11847997681.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000064e4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x64E4 5100 bytes
SHA-256: 96ca12d95f7165d7f8397c9c2e33a566dc672f96530c43f213d20bc25c7f4bda
font_01_sfnt_off00007616.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7616 10608 bytes
SHA-256: 6a8294e60255981b8cf384d1a44aa5b31135494abf490e86bc8c507c9b9083a0
font_02_sfnt_off00009a31.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9A31 4324 bytes
SHA-256: 0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333