Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1cd723d6ba6edd4…

MALICIOUS

PDF

51.2 KB Created: 2020-09-16 14:33:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d0ff935f66784ac0661b1cc0186e27e9 SHA-1: d5aa6055ed2606c579f7219a1c663c401427950b SHA-256: f1cd723d6ba6edd45998fcaa7ea677527cf825222614fe0d086f17b995053139
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to suspicious domains and are flagged as part of a link farm. One prominent URL, 'https://ttraff.club/wix?keyword=overview+clues+to+earth%2527s+past+answer+key', is identified as a malicious redirector. The document body, though heavily obfuscated, contains similar URLs, suggesting a coordinated effort to direct users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=overview+clues+to+earth%2527s+past+answer+key
    • http://files.choestoebaptistchurch.org/uploads/1/3/1/6/131607163/mofojajoku.pdf
    • http://files.bedbugsremoval.com.au/uploads/1/3/2/3/132302926/favuraxoduzut.pdf
    • http://rarujinaf.objectpages.com/uploads/1/3/1/4/131453872/jogadug_falerun_visimuleve_fibawesazu.pdf
    • http://mefozaneb.litturi-photography.com/uploads/1/3/2/7/132710567/rijusiwub.pdf
    • http://files.knightsautowash.com/uploads/1/3/0/7/130776386/8500239.pdf
    • https://cdn.shopify.com/s/files/1/0431/7600/1704/files/34440505086.pdf
    • https://cdn.shopify.com/s/files/1/0434/8814/9654/files/javarukaxalaveku.pdf
    • https://f092bec7-e105-4e44-bf20-fd1eeb3e23a5.filesusr.com/ugd/3ed902_2a3d1838a4b74895b3e579fa5df878be.pdf?index=true
    • https://4ae5a20e-6764-4ec4-8b01-9c7529a94cc3.filesusr.com/ugd/80bfa9_4245df53cec44fad86b53369f6b08c02.pdf?index=true
    • https://b5b3e5c8-5807-4c85-8f27-8b7d0e237dac.filesusr.com/ugd/0b46e6_fad31ae4cc0142ae94257b70600cef2c.pdf?index=true
    • https://4a81779e-23ba-4f1c-a811-b8f781134158.filesusr.com/ugd/48bf55_020351a9c4534ce28007d6160f1757ac.pdf?index=true
    • https://d2d7aba7-83de-475f-93cc-e9bdccb07b1c.filesusr.com/ugd/0b46e6_3050af66f4c549eb94a2d7c847e203c3.pdf?index=true
    • https://d33ba8b3-a666-4303-9248-0610a85f1f8e.filesusr.com/ugd/2994dd_d1cc7326e39349f4938ea291edcefcf0.pdf?index=true
    • https://c8fbccee-eb0d-48f7-8803-1b3fd3406348.filesusr.com/ugd/565485_5c3bc1dd35e04de8a109a1218113982e.pdf?index=true
    • https://bd9b38d7-755e-4204-9950-d5a349025850.filesusr.com/ugd/b90ba1_659f2b9359ab4388bd4ab538be37f80c.pdf?index=true
    • https://dd894573-7770-4b88-9555-d0d04f311cde.filesusr.com/ugd/430cb2_e449efa94ff84538be7efa76e6801277.pdf?index=true
    • https://19867a25-dc77-425f-97a9-ab14bda4a674.filesusr.com/ugd/9df9d6_d200703251a848a6b97a32655d8de01f.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008a87.bin
346dd93939193190cde96645f66aec3542cdfedef345a642fa86f1643b77b00e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A87 5400 bytes
font_01_sfnt_off00009d00.bin
8d7dc922b448f0300acb03b34be37ff3bcf8685abf004096bf763fc3f903cbfe
pdf-font-stream PDF embedded font (sfnt) at offset 0x9D00 10072 bytes