Malicious PDF — malware analysis report

Static analysis result for SHA-256 27eb763e04193143…

MALICIOUS

PDF

46.5 KB Created: 2020-08-15 06:16:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1c43014bd96b012f2730ac44c05909e9 SHA-1: e5bbe91a218477bc6d5de1da8b857ec964cac3be SHA-256: 27eb763e04193143ae1e5b0108f1bd6f705585eb582a77699c408285d4dd1792
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document was flagged as malicious by an ML classifier and contains a high number of embedded links. One critical heuristic indicates that the PDF links to known malicious redirector infrastructure, specifically 'ttraff.cc'. The document body contains obfuscated text and multiple URLs, including the redirector and numerous links hosted on 'cdn.shopify.com' and other domains, suggesting a link farm or redirection scheme. The primary intent appears to be directing users to malicious content through a chain of redirects.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=ff14+gunbreaker+job+guide
    • http://kejapujol.kirkmahoe.com/uploads/1/3/1/3/131380183/kipevexuk.pdf
    • https://cdn.shopify.com/s/files/1/0430/4178/3959/files/bacteria_bioremediation.pdf
    • https://cdn.shopify.com/s/files/1/0433/5216/2462/files/kokuxeja.pdf
    • https://cdn.shopify.com/s/files/1/0432/1778/0896/files/vuxigopeparaseleti.pdf
    • https://cdn.shopify.com/s/files/1/0427/9032/2342/files/26718555780.pdf
    • https://cdn.shopify.com/s/files/1/0427/5788/2022/files/42878906246.pdf
    • https://cdn.shopify.com/s/files/1/0436/1738/6659/files/dapiroturavo.pdf
    • https://cdn.shopify.com/s/files/1/0430/5666/0633/files/tidabigakima.pdf
    • https://cdn.shopify.com/s/files/1/0429/9823/5289/files/locust_rider_osrs.pdf
    • https://cdn.shopify.com/s/files/1/0438/6829/1227/files/73198114333.pdf
    • https://cdn.shopify.com/s/files/1/0434/1733/8005/files/capitalize_first_letter_javascript.pdf
    • https://cdn.shopify.com/s/files/1/0430/3791/7345/files/27940669442.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/savowogofoxifonikili.pdf
    • https://cdn.shopify.com/s/files/1/0431/0522/2813/files/vekebib.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000067a2.bin
e733470317f429787ac8c76789816beee384add1a4cf47b477feb498b4477337
pdf-font-stream PDF embedded font (sfnt) at offset 0x67A2 5044 bytes
font_01_sfnt_off000078e6.bin
cf3be47f0b0ab93cc797ff5a6cc35d0a92c572cd2d5734678689743b222f97ad
pdf-font-stream PDF embedded font (sfnt) at offset 0x78E6 11760 bytes
font_02_sfnt_off00009f40.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F40 4324 bytes