Malicious PDF — malware analysis report

Static analysis result for SHA-256 eec16e75417092a6…

MALICIOUS

PDF

42.4 KB Created: 2020-08-13 21:57:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cf62be0deb8712f3390ad74c7f0db573 SHA-1: 30899698cd19dee204d1652ede972b99bb7def99 SHA-256: eec16e75417092a6871be359d5efc3cf997bc20019851825bbda0293872c906e
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document exhibits characteristics of a link farm, embedding numerous external links. One prominent link directs to a redirector service, ttraff.com, which is often used to obfuscate malicious destinations. The ML classifier strongly flagged this PDF as malicious, supporting the assessment that it is designed to lead users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=importance+of+international+marketing+information+system
    • http://mevoz.notyouraveragechurchgirl.org/uploads/1/3/0/7/130776394/xijewenas.pdf
    • http://files.cateringandcreations.net/uploads/1/3/0/8/130814513/9295549.pdf
    • http://gefekuxo.stseachnalls.ie/uploads/1/3/1/1/131164250/suvape.pdf
    • http://files.neussephotography.com/uploads/1/3/2/8/132814544/fotimalesizamej_deparadesejek_ginemukub.pdf
    • https://cdn.shopify.com/s/files/1/0432/9635/8565/files/e9_ad_94_e7_a5_9ez.pdf
    • https://cdn.shopify.com/s/files/1/0435/7111/8235/files/author_s_purpose_worksheets_with_answers.pdf
    • https://cdn.shopify.com/s/files/1/0435/5964/9429/files/33303244100.pdf
    • https://cdn.shopify.com/s/files/1/0452/4628/3937/files/10th_maths_textbook_download.pdf
    • https://cdn.shopify.com/s/files/1/0440/6339/1894/files/a_guide_to_sql_8th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0434/2490/7414/files/alfabeto_e_numeros_em_ingles.pdf
    • https://cdn.shopify.com/s/files/1/0431/0522/2818/files/67873690755.pdf
    • https://cdn.shopify.com/s/files/1/0431/8999/3635/files/thyroid_disease_in_pregnancy_rcog.pdf
    • https://cdn.shopify.com/s/files/1/0440/4881/0149/files/mowon.pdf
    • https://cdn.shopify.com/s/files/1/0449/1811/2423/files/employment_insurance_compassionate_care_benefits.pdf
    • https://cdn.shopify.com/s/files/1/0433/7994/9718/files/sidiposejawukevukeluk.pdf
    • https://cdn.shopify.com/s/files/1/0430/8025/3593/files/pezosu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000641e.bin
523a24466819f50c96f12b484b214135688c18d957f7c03fc827ea19089624f2
pdf-font-stream PDF embedded font (sfnt) at offset 0x641E 5436 bytes
font_01_sfnt_off00007689.bin
6dce771efb79976ed401a7fa91928136d87aec3318f6991ad06df34a05b632b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x7689 11084 bytes