Malicious PDF — malware analysis report

Static analysis result for SHA-256 e6939cd5d1488445…

MALICIOUS

PDF

48.1 KB Created: 2020-09-02 00:13:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f33b71ba1762ab52e11d89a3f56495ab SHA-1: cbdd2d9070c69b2a17299e52f7105872810fb28b SHA-256: e6939cd5d1488445d57303bdaa01e67049f89f434280a5c748dd7479bbe236b5
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

This PDF file contains a large number of embedded links, many pointing to external PDF documents hosted on static.usrfiles.com. One of these links, https://ttraff.com/wix?keyword=wilson+occurrence+reporting+system, is flagged as a known malicious redirector. The presence of a link farm and a malicious redirector suggests the document is part of a campaign to distribute malware or conduct phishing, rather than serving legitimate content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=wilson+occurrence+reporting+system
    • https://static.usrfiles.com/ugd/bfbc46_fa01cd7e252d44aa96acdda41c091a5f.pdf
    • https://static.usrfiles.com/ugd/33a16d_cf0c25f18c454780baf9d884872ac342.pdf
    • https://static.usrfiles.com/ugd/65b209_a6185f8251114e5e83d5fc57bda40320.pdf
    • https://static.usrfiles.com/ugd/3eed2b_3c8b8b1149904c12892b7c7a3bfb6545.pdf
    • https://static.usrfiles.com/ugd/9cb927_57971524ed9946f5b7a833ddcccda47e.pdf
    • https://static.usrfiles.com/ugd/0bfb20_9abb955cdf2649588b15eb600bcb64d0.pdf
    • https://static.usrfiles.com/ugd/b56239_6e99191880ce40a1a974b77556dbeec8.pdf
    • https://static.usrfiles.com/ugd/01e791_fc58419edd0344cb88afca54fa672411.pdf
    • https://cdn.shopify.com/s/files/1/0450/5144/5400/files/what_are_values_and_beliefs.pdf
    • https://cdn.shopify.com/s/files/1/0434/5135/1207/files/78348204619.pdf
    • https://cdn.shopify.com/s/files/1/0438/7025/7320/files/wemukawuveze.pdf
    • https://cdn.shopify.com/s/files/1/0437/2883/0632/files/54275028048.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007c56.bin
b7249d1e323084727cb1a2af6af494d5ff9295e618766ba0fb89431e37c18dd2
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C56 5160 bytes
font_01_sfnt_off00008deb.bin
621612050479b49732137e2d8df812a4b64ba251d6735db29371bcd3b7df6cae
pdf-font-stream PDF embedded font (sfnt) at offset 0x8DEB 10680 bytes