Malicious PDF — malware analysis report

Static analysis result for SHA-256 fb150a28f980989d…

MALICIOUS

PDF

46.9 KB Created: 2020-08-29 14:51:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: de755f07fd7854c43dbe2ae4dbae0e7f SHA-1: 0ac8739fa7fea4b0f63e55b48c6fb5c3b3476bc2 SHA-256: fb150a28f980989d5e290473fde142d633c6c51ca1a36dcaa5066775e40545d7
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged as malicious by a machine learning classifier and contains a critical heuristic indicating it links to known malicious redirector infrastructure. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs pointing to external resources. The primary malicious URL identified is https://ttraff.cc/wix?keyword=concepto+de+escritura+segun+daniel+c, which is likely used to funnel victims to further malicious sites. The document body contains garbled text and the wkhtmltopdf application name, suggesting it was programmatically generated.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=concepto+de+escritura+segun+daniel+c
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/62222626122.pdf
    • https://cdn.shopify.com/s/files/1/0429/7284/0090/files/33911257695.pdf
    • https://cdn.shopify.com/s/files/1/0429/8424/3351/files/zupiluw.pdf
    • https://cdn.shopify.com/s/files/1/0429/1608/5916/files/grade_11_chemistry_test_questions_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0430/4420/8789/files/nulofirenupigawekuxasogi.pdf
    • https://cdn.shopify.com/s/files/1/0434/8359/4917/files/jaralaputunu.pdf
    • https://cdn.shopify.com/s/files/1/0427/8334/2748/files/92315108847.pdf
    • https://static.usrfiles.com/ugd/b8c837_f44395fece5340d8b2952a9db3289c90.pdf
    • https://static.usrfiles.com/ugd/b8c837_bfb518c5d59a49098f26597b10d0cccc.pdf
    • https://static.usrfiles.com/ugd/b8c837_7268ad4c4e5245bcb3adf9abdd045fae.pdf
    • https://static.usrfiles.com/ugd/b8c837_db432302575d4badb9a9a30699d2c826.pdf
    • https://static.usrfiles.com/ugd/b8c837_a811c98b19fb400c9221fc933725b746.pdf
    • https://static.usrfiles.com/ugd/b8c837_ffb888ccdff74888b90bfa85a1dd202f.pdf
    • https://static.usrfiles.com/ugd/f3ecbe_ffab4937db4b45ccafaefdef6f48a844.pdf
    • https://static.usrfiles.com/ugd/b8c837_517b4ec932634a7c88d540facb71d5c9.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000072b2.bin
7a099060444aeffddef64e34d2cddb1fc146efa5a4eb61540722e67f394ce8f0
pdf-font-stream PDF embedded font (sfnt) at offset 0x72B2 5144 bytes
font_01_sfnt_off00008439.bin
af4459c3f89d248bce3aab2efa867ac5d542452147c5532f874f67d697dec40a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8439 12356 bytes