Malicious PDF — malware analysis report

Static analysis result for SHA-256 e295c7dd10ee4c14…

MALICIOUS

PDF

43.4 KB Created: 2020-08-20 19:49:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d49947b427fcbe54bf66dbc9fb84d8a2 SHA-1: 732e727664e80a5c9f0e1ac5f30bf5abf226dec0 SHA-256: e295c7dd10ee4c14736fe41946e12f3fd580363e56e088e550f3f6577dd49627
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a significant number of embedded links, many of which point to external PDF files hosted on Shopify.com. This behavior is indicative of a PDF SEO link farm, designed to manipulate search engine rankings. One of the embedded links, https://ttraff.com/pify?keyword=oecd+transfer+pricing+guidelines+interquartile+range, is flagged as a known malicious redirector, suggesting a potential for further malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=oecd+transfer+pricing+guidelines+interquartile+range
    • http://files.professional-tourguides.com/uploads/1/3/2/7/132712251/2153572.pdf
    • http://files.robinlewismusic.com/uploads/1/3/1/8/131871994/b9f068.pdf
    • http://files.accordeon.co/uploads/1/3/1/1/131164236/dujafajow.pdf
    • https://cdn.shopify.com/s/files/1/0433/4993/4229/files/wekawazowewegam.pdf
    • https://cdn.shopify.com/s/files/1/0431/6525/3789/files/boston_legal_season_1_episode_1.pdf
    • https://cdn.shopify.com/s/files/1/0434/3165/7638/files/lulijovejuwad.pdf
    • https://cdn.shopify.com/s/files/1/0434/6275/4461/files/77314445382.pdf
    • https://cdn.shopify.com/s/files/1/0436/5962/4606/files/benzenoid_aromatic_compounds.pdf
    • https://cdn.shopify.com/s/files/1/0431/1223/5159/files/17019157554.pdf
    • https://cdn.shopify.com/s/files/1/0432/5831/4912/files/86358461415.pdf
    • https://cdn.shopify.com/s/files/1/0431/4395/4594/files/87418690701.pdf
    • https://cdn.shopify.com/s/files/1/0436/2777/4115/files/pediatric_hematology_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/7960/6176/files/pogoda_angielski_wiczenia_dla_dzieci.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b9c.bin
04019556820568f638df0383c360747869bcf5f83760880d9ceb5395d0b0b74a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B9C 5476 bytes
font_01_sfnt_off00007e3b.bin
d1ccb39f1ad611c8c644b18fa96342e444c1c07ce1387d9d3b6cb61500e3b1e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E3B 10080 bytes