Malicious PDF — malware analysis report

Static analysis result for SHA-256 e6f74dbbb469bd46…

MALICIOUS

PDF

38.6 KB Created: 2020-08-21 07:38:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c5642b6ae796b78a69f9493fc2f75acb SHA-1: 72e2ecf32129cfd47066264f0596b27fed5262dc SHA-256: e6f74dbbb469bd46497cf72e59d6dc6a986a7e69c1b8bc34795829d6d43fbaac
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

This PDF document contains a link to a known malicious redirector, ttraff.com, which is likely used to host phishing content. The document also features a large number of embedded links to PDFs hosted on Shopify, suggesting a link farm or SEO poisoning attempt. The ML classifier strongly indicated maliciousness, and the PDF structure itself points to malicious redirection. No scripts were extracted, but the embedded links are sufficient to infer a phishing or malicious redirection attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=fishing+sim+world+boss+guide
    • http://tudonawi.slamproject.org/uploads/1/3/2/6/132680813/c400b801158e.pdf
    • http://files.berkeleywellbeing.com/uploads/1/3/2/6/132695280/6966365.pdf
    • http://files.charlottesarthistory.com/uploads/1/3/1/6/131606666/e3d3d7.pdf
    • https://cdn.shopify.com/s/files/1/0428/3075/8054/files/74848631731.pdf
    • https://cdn.shopify.com/s/files/1/0431/4782/1205/files/rusozelapadejibuninefowab.pdf
    • https://cdn.shopify.com/s/files/1/0431/9015/7474/files/xubupuredigewigixugo.pdf
    • https://cdn.shopify.com/s/files/1/0431/7793/5004/files/vakajitadidikemiv.pdf
    • https://cdn.shopify.com/s/files/1/0437/5799/4142/files/concepto_de_insuficiencia_cardiaca.pdf
    • https://cdn.shopify.com/s/files/1/0438/4092/9957/files/what_is_an_example_of_orthography.pdf
    • https://cdn.shopify.com/s/files/1/0430/0167/5939/files/chuyn_t_file_sang_file_nh_online.pdf
    • https://cdn.shopify.com/s/files/1/0429/2929/1427/files/cengage_chemistry_book_download.pdf
    • https://cdn.shopify.com/s/files/1/0432/5244/9444/files/pojurebu.pdf
    • https://cdn.shopify.com/s/files/1/0433/9574/3907/files/98676414108.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005933.bin
f28abd7b29e18564bad818ca02217a685f8a9911c12d81b6bb38c766fabe6573
pdf-font-stream PDF embedded font (sfnt) at offset 0x5933 5216 bytes
font_01_sfnt_off00006acc.bin
e663d74fa8fa0902404d214cb6d90bdffc77f1fe05cb9c00bb753191ee7a6fdc
pdf-font-stream PDF embedded font (sfnt) at offset 0x6ACC 10420 bytes