Malicious PDF — malware analysis report

Static analysis result for SHA-256 27fd1d69426837df…

MALICIOUS

PDF

60.2 KB Created: 2020-08-16 16:59:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 003ff05108b0e4e4916e57b51019750f SHA-1: 4f45f6d0dabc59af06a6ec24ea9e87263881436d SHA-256: 27fd1d69426837df6dc65705c201f43ac810c656779cb0b15b491529d34da377
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. This indicates the document's primary purpose is to redirect users to malicious infrastructure. The PDF also contains a large number of external links, many hosted on Shopify, which is characteristic of SEO link farm abuse to improve search engine ranking for malicious content. The ML classifier strongly supports the malicious nature of this PDF. No scripts were extracted, but the embedded URLs and the PDF structure strongly suggest a phishing or malware distribution lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=arabic+vocabulary+for+beginners+pdf
    • http://jeponerup.sweet-williams.com/uploads/1/3/1/4/131406082/c491c4d34db66.pdf
    • http://tulapopu.rebeccafreesemd.com/uploads/1/3/0/7/130739561/05bbbcdc34450.pdf
    • http://files.funlove2go.com/uploads/1/3/1/4/131453588/vevupitomabusewefo.pdf
    • https://cdn.shopify.com/s/files/1/0432/8649/5396/files/investigating_biology_lab_manual.pdf
    • https://cdn.shopify.com/s/files/1/0430/4227/5485/files/93585795757.pdf
    • https://cdn.shopify.com/s/files/1/0437/2014/7112/files/mavubugadapumibetuli.pdf
    • https://cdn.shopify.com/s/files/1/0428/7945/1295/files/wapofevosavufazukevogaw.pdf
    • https://cdn.shopify.com/s/files/1/0437/6661/2119/files/kozulalufo.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/muzoguganava.pdf
    • https://cdn.shopify.com/s/files/1/0437/1608/3877/files/622726736.pdf
    • https://cdn.shopify.com/s/files/1/0431/1361/1421/files/biwazalapabesavolelipik.pdf
    • https://cdn.shopify.com/s/files/1/0431/9631/7845/files/ravish_kumar_book_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0438/0216/5410/files/surf_city_surf_cam.pdf
    • https://cdn.shopify.com/s/files/1/0437/5799/4138/files/48923408796.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0000b03c.bin
53689aa766cd2bd66f61b5b489b97e24b98f6953274f8b5fe201b748288b28cc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xB03C 29152 bytes
font_00_sfnt_off0000720f.bin
4a7905c721899766fa2f95951a361d8d8e470739aa967ca88aa0b80125f79b06
pdf-font-stream PDF embedded font (sfnt) at offset 0x720F 5616 bytes
font_01_sfnt_off00008543.bin
9229c9ab066e0e944560438e787ff6738e68eae9df8c24c5286875dfd92599f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x8543 13516 bytes