Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e96f4a299c6bcff…

MALICIOUS

PDF

44.8 KB Created: 2020-07-27 21:07:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 123a121886cde8df0ee40767f21e2da5 SHA-1: 3e89988a1ae8ab3fd24fe8bde452afff904ec8e9 SHA-256: 0e96f4a299c6bcff8fe82aa2c0c53d5668aa310e7e2e95fca16633d21d4aeca3
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many pointing to Shopify domains hosting other PDFs, suggesting a link farm or SEO manipulation tactic. One critical heuristic identified a link to a known malicious redirector, ttraff.cc, which is likely the primary malicious intent. The ML classifier also strongly indicated maliciousness. No scripts were extracted, but the presence of numerous links and the redirector heuristic are sufficient to assess the attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=vsts+yaml+build+number+format
    • http://files.thebrowneyedsusan.com/uploads/1/3/0/7/130739626/8129586.pdf
    • http://files.bestprimeproperties.com/uploads/1/3/0/7/130739147/00575779fc.pdf
    • http://files.skillmillnyc.com/uploads/1/3/0/8/130873728/70fb99b1.pdf
    • http://files.karyntunks.com/uploads/1/3/0/8/130874276/4896255.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0430/0016/8597/files/zuzedozodonebedekag.pdf
    • https://cdn.shopify.com/s/files/1/0432/2210/6271/files/sugidode.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/69262577592.pdf
    • https://cdn.shopify.com/s/files/1/0437/5475/0106/files/98826398879.pdf
    • https://cdn.shopify.com/s/files/1/0432/9324/5590/files/bivosu.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/13170590630.pdf
    • https://cdn.shopify.com/s/files/1/0434/9827/4978/files/87945915232.pdf
    • https://cdn.shopify.com/s/files/1/0431/5673/4109/files/4786309102.pdf
    • https://cdn.shopify.com/s/files/1/0429/0124/2022/files/zitajatiwupuxuvu.pdf
    • https://cdn.shopify.com/s/files/1/0434/4299/5352/files/20943924410.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/71419102660.pdf
    • https://cdn.shopify.com/s/files/1/0434/3581/9173/files/fivinuduladikokazunupo.pdf
    • https://cdn.shopify.com/s/files/1/0428/7044/0095/files/57950274315.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000070d1.bin
f34f37ccb4d1a61dbaa2326280f0bb9aee569811d41e259bd5b779e88c77bfbb
pdf-font-stream PDF embedded font (sfnt) at offset 0x70D1 5144 bytes
font_01_sfnt_off00008231.bin
28667682b72899474c828e00d327255bb32ee88c5e110ba683d2a732cb51d44e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8231 10492 bytes