Malicious PDF — malware analysis report

Static analysis result for SHA-256 2606d12118a7bb3a…

MALICIOUS

PDF

73.3 KB Created: 2020-08-30 02:18:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9aa49114bbd47eab7c74662b3e51f024 SHA-1: ea4c2c507e5119b9ee31198c98899a036a5c6602 SHA-256: 2606d12118a7bb3ab090b45780695bde9945de642ff51dd89303ac5f17ff022a
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. This indicates the document is designed to lure users to a potentially harmful website. The PDF also exhibits characteristics of a link farm, with numerous embedded URLs, many pointing to Shopify domains, suggesting an attempt to obscure the final malicious destination. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=john+fogerty+and+martha+paiz+photos
    • https://static.usrfiles.com/ugd/b8c837_61aa954e9a2c416e8cf530f4bbf5c2ce.pdf
    • https://static.usrfiles.com/ugd/b52961_e5f085b7f3cb42d486652c17ae4ec482.pdf
    • https://static.usrfiles.com/ugd/3e9e83_9389a409b08e4917a2bbe853057a0472.pdf
    • https://cdn.shopify.com/s/files/1/0430/1560/2337/files/zodota.pdf
    • https://cdn.shopify.com/s/files/1/0433/8896/0933/files/dulanuvegakiza.pdf
    • https://cdn.shopify.com/s/files/1/0430/7012/8277/files/ripek.pdf
    • https://cdn.shopify.com/s/files/1/0431/4418/3970/files/30405068235.pdf
    • https://cdn.shopify.com/s/files/1/0429/2778/4099/files/argos_uk_catalogue.pdf
    • https://cdn.shopify.com/s/files/1/0434/0695/0550/files/dabojeriwuw.pdf
    • https://cdn.shopify.com/s/files/1/0428/8118/8003/files/jasixo.pdf
    • https://cdn.shopify.com/s/files/1/0432/4183/2615/files/meratizugasapavenedigar.pdf
    • https://cdn.shopify.com/s/files/1/0433/4528/1183/files/hampton_bay_antigua_ceiling_fan.pdf
    • https://cdn.shopify.com/s/files/1/0437/8863/2213/files/application_vnd_ms_word.pdf
    • https://static.usrfiles.com/ugd/b8c837_bc4b5000d7e140c89d5fb2220bad0f8b.pdf
    • https://static.usrfiles.com/ugd/dd4472_1b8bd657e2ba434f9978bc20d7132c14.pdf
    • https://static.usrfiles.com/ugd/b8c837_78becd815b094071a59ceb8afbc0b874.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d03c.bin
a634e93cf1c49e98f85f81f05aec8528eb269f0b646c31b9b8da36f87e192ebb
pdf-font-stream PDF embedded font (sfnt) at offset 0xD03C 5352 bytes
font_01_sfnt_off0000e24c.bin
27716c11f23c9ab3ee5b2ba7c9b9945b7136f15913c0a9bb450736784087c674
pdf-font-stream PDF embedded font (sfnt) at offset 0xE24C 11800 bytes
font_02_sfnt_off00010987.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x10987 4324 bytes